Trezor: 347,000 Customers Targeted in Brevo Phishing

Trezor reports attackers used a Brevo SSO breach to send phishing emails to 347,000 customers; about 2,500 clicked a malicious link before the site was taken down.

Trezor says attackers used a breach at email marketing provider Brevo to send phishing messages to 347,000 of its customers. The company reported that roughly 2,500 recipients clicked a link in the fraudulent email before the malicious site was taken offline about 20 minutes after detection.

Brevo described the method used to gain access as an exploit of its SAML single sign-on (SSO) process. Brevo wrote: “This access was not properly scoped: instead of being limited to the single organization where SSO was enabled, it wrongly granted the attacker access to all organizations those users could reach.” The firm said the attacker created a Brevo account, enabled SSO on it and invited legitimate Brevo users into that configuration, then used their own identity provider to sign in as those invited users.

Brevo reported the attacker accessed 138 Brevo accounts in total. The threat actor used six of those accounts to send phishing messages and exfiltrated contact lists from 43 accounts. One of the abused contact lists contained the 347,000 email addresses tied to Trezor’s campaign.

The phishing emails used the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and directed recipients to a malicious website. Trezor warned customers that entering wallet backup phrases or other backup data on that site could lead to loss of funds. The company has not disclosed how many users lost funds or the total value affected.

Swiss hardware wallet maker BitBox and crypto tax tool CoinTracking also reported receiving similar emails linked to the Brevo incident, though they have not detailed the source or the scope of their exposure.

The Brevo incident follows a separate data breach affecting Trezor customers via its shipping partner ShipMonk. Trezor previously disclosed that personal information for nearly 14,000 people was exposed and later updated the impact to include an additional 67,000 U.S. customers, including names, emails, shipping addresses, phone numbers and order numbers.

Brevo said it is investigating the incident and working with affected customers to contain the impact. Trezor notified customers of the phishing campaign and advised anyone who clicked the link to check their wallets, move funds to secure devices if needed, and never enter seed phrases or backup data on web pages.

Articles by this author