NG Solution Team
Cybersecurity

Trezor newsletter hijacked via Brevo breach to phish 347,000 users

An attacker used a flaw in email platform Brevo to send phishing messages from the verified newsletter accounts of Trezor, BitBox and CoinTracking, targeting 347,000 Trezor subscribers in a bid to steal wallet seed phrases.

Trezor newsletter used to phish 347,000 subscribers

The campaign began after an attacker discovered a login flaw at Brevo on September 9, 2026. The attacker sent a message to Trezor’s full mailing list, titled “Critical Security Alert: STM32 Entropy Vulnerability,” warning that the microcontroller inside the hardware wallet could leak seed phrases to a brute-force attack. The email contained a link to a fraudulent verification tool designed to harvest seed phrases. Trezor disabled the malicious domain about 20 minutes after detecting the campaign; by then roughly 2,500 recipients had already clicked the link. No funds have been confirmed stolen.

How Brevo’s SSO flaw let the attacker move between accounts

Brevo said the attacker created their own Brevo account, enabled single sign-on (SSO) on it, then invited legitimate Brevo customers into that SSO setup and used the attacker’s identity provider to sign in as those invited users. The access was supposed to remain scoped to the single organization where SSO had been enabled, but an authorization boundary failed and the attacker gained reach into other organizations those invited users could access, including the newsletter accounts of Trezor, BitBox and CoinTracking.

Brevo reported that 138 accounts were touched in total. Six of those accounts were used to send phishing emails. Contacts were exported from 43 accounts. The remaining 93 accounts showed no meaningful activity, suggesting the attacker was mapping access before Brevo intervened. Brevo said it closed the route used by the attacker at 08:30 UTC (10:30 CEST) on September 10, 2026, signed out every user on the platform and is contacting affected customers directly.

CoinTracking subscribers received a different lure: an email with the subject line “Data Breach Notice: Please refresh API keys as soon as possible,” urging users to hand over live API access to portfolio and tax data. BitBox’s account was also compromised, though Brevo has not provided the same level of detail about the volume of messages sent through that account.

The incident underlines a broader risk for security-focused brands: marketing and email platforms that sit outside a company’s audited security perimeter can become attack vectors. Brevo says more than 600,000 customers globally use its platform across fintech, ecommerce, software and other sectors, meaning an SSO scoping bug can affect many industries and trusted communication channels.

Related posts

AI-generated fake cases flagged in San Antonio ISD appeal

Emily Brown

Is CISA warning about three actively exploited SharePoint vulnerabilities?

James Smith

Has Tata Electronics’ cybersecurity breach impacted its business?

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy