NG Solution Team
Cybersecurity

Brevo login flaw let phishing reach 347,000 Trezor subscribers

An attacker exploited a flaw in email platform Brevo’s login system to access 138 client accounts, enabling a phishing email to reach roughly 347,000 Trezor newsletter subscribers and similar fraudulent messages to be sent from accounts belonging to BitBox and CoinTracking.

Brevo login flaw and authorization boundary failure

Brevo said in a postmortem that the attacker created a Brevo account, enabled single sign-on (SSO) and invited legitimate Brevo users into that configuration. Access should have been confined to the attacker’s organization, Brevo said, but an authorization boundary failed and granted access to every organization the invited users could reach. The company reported 138 client accounts were accessed; six accounts were used to send phishing emails, contacts were exported from 43 accounts and 93 accounts showed no meaningful activity. Brevo did not specify whether those categories overlapped.

A reporter contacted Brevo for further comment but did not receive a response before publication.

Impact on Trezor, BitBox and CoinTracking

Trezor said the phishing message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” contained a link to an app that requested users’ wallet backups. The company disabled the domain at the DNS level within 20 minutes, but about 2,500 people accessed the link before the takedown. A Trezor spokesperson said the initial email was sent to 347,000 customers, all of whom were subsequently contacted. Trezor added its Brevo account stored only opt-in newsletter email addresses and no other customer data.

The Trezor spokesperson said: “Until we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.”

A BitBox spokesperson said the unauthorized email was sent through Brevo and appeared to have reached its full newsletter and tutorial list. BitBox said Brevo held only email addresses and language preferences, found no evidence of compromised company credentials, downloaded contacts, lost funds or disclosed recovery phrases, and is treating the list as potentially accessed while it awaits Brevo’s logs.

CoinTracking said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible” and warned recipients not to follow the email’s links.

Related posts

Has Craneware reported unauthorized access and file exfiltration? Alternatives: – Has Craneware suffered unauthorized access and file exfiltration? – Has Craneware experienced a data breach with file exfiltration?

Emily Brown

Trezor Users Targeted via Compromised Email Service

David Jones

How can specialized agents improve security alert triage on Databricks?

Jessica Williams

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy