Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News

    Brevo Login Flaw Linked to Phishing Attacks on 347K Trezor Users

    1 hour ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Brevo Login Flaw Linked To Phishing Attacks On 347k Trezor Users
    Brevo Login Flaw Linked To Phishing Attacks On 347k Trezor Users

    Brevo, an email delivery platform used across the crypto industry, disclosed that an attacker leveraged a login-system weakness to gain access to multiple client accounts. The incident allowed phishing messages to be sent to a combined audience of roughly 347,000 Trezor newsletter subscribers, with additional campaigns also reaching audiences tied to BitBox and CoinTracking.

    In a Thursday postmortem, Brevo said the attacker used six accounts to send phishing emails. It also reported that contacts were exported from 43 accounts, while 93 accounts showed no meaningful activityโ€”though Brevo did not clarify whether those categories overlap. Brevo added that the access-control boundary that should have limited the attackerโ€™s reach to a single organization failed.

    Key takeaways

    • Brevo reported that an authorization boundary failed after an attacker configured an account with single sign-on and invited real users into the setup.
    • At least six Brevo accounts were used to send phishing emails.
    • Trezor says the initial phishing email was sent to about 347,000 newsletter customers, and it is treating those addresses as potentially exposed.
    • BitBox and CoinTracking also confirmed unauthorized newsletter activity routed through Brevo, though they reported no evidence of lost funds or exposed recovery phrases.

    How Brevoโ€™s login flaw enabled cross-account access

    Brevoโ€™s postmortem describes a pathway in which an attacker created a Brevo account, turned on single sign-on, and then invited legitimate Brevo users into the configuration. Brevo said the design should have confined access to the organization associated with the configuration, but the authorization boundary did not hold.

    As a result, the attacker was able to reach every organization the invited users could access. Brevoโ€™s write-up links the exposure directly to this breakdown in access controls, rather than to a breach of the affected organizationsโ€™ own systems.

    The incident surfaced publicly after warnings from Trezor and BitBox earlier in the week, which pointed to their shared email provider and explained why the fraudulent emails appeared credible and passed ordinary authentication checks.

    Phishing mechanics: what recipients were asked to do

    Trezor said the phishing emailโ€”titled โ€œCritical Security Alert: STM32 Entropy Vulnerabilityโ€โ€”included a link to an app designed to solicit wallet backups. According to Trezor, the company disabled the domain at the DNS level within about 20 minutes. Even with the rapid takedown, Trezor reported that about 2,500 people accessed the link before it was blocked.

    Trezor also emphasized the broader risk to its subscriber list. In comments provided to Cointelegraph, a Trezor spokesperson said the initial email was sent to 347,000 customers, and that all recipients were subsequently contacted about the danger.

    The spokesperson added: โ€œUntil we hear more from Brevo, we are treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.โ€ Trezor further stated that its Brevo account stored only opt-in newsletter email addresses and no other customer data.

    Hardware wallet and crypto services respond: exposure without confirmed credential theft

    BitBox told Cointelegraph that its unauthorized email was delivered through Brevo and appeared to reach its full newsletter and tutorial audience.

    In its response, BitBox said Brevo held only email addresses and language preferences for it. BitBox reported no evidence of compromised company credentials, no indication that attackers downloaded data beyond the newsletter contacts, and no signs of funds being stolen or recovery phrases disclosed. Still, it said it is treating the list as potentially accessed while awaiting Brevoโ€™s logs.

    CoinTracking, meanwhile, reported separate phishing activity. The company said its Brevo account distributed an email titled โ€œData Breach Notice: Please refresh API Keys as soon as possible.โ€ CoinTracking warned recipients not to click the links in the message, indicating that the main threat was credential-related phishing rather than immediate compromise of underlying systems.

    Together, the responses underline a common pattern in third-party email incidents: the most immediate harm may be messaging-based, but the bigger operational concern is whether contact lists can be reused for follow-on attacks.

    What Brevo disclosedโ€”and what remains unclear

    Brevoโ€™s incident report focuses on the account-access path, but some details remain ambiguous for downstream victims. Brevo said contact exports occurred across 43 accounts and that 93 accounts showed no meaningful activity, without specifying whether those numbers overlap or how many organizations were fully affected end-to-end.

    Brevo also did not provide, in the disclosed summary, a precise mapping from the six sending accounts to the different affected crypto companiesโ€™ audiences. Cointelegraph attempted to request additional information from Brevo but received no response before publication.

    For investors, traders, and builders, the relevance extends beyond the immediate phishing harm: reputable crypto firms rely on email service providers to communicate security alerts, product updates, and documentation. When those communications channels can be abusedโ€”especially when phishing content looks authenticโ€”users may face repeated attempts that target them again using addresses already in the attackerโ€™s possession.

    Going forward, recipients of such newsletters should be cautious about any unexpected security prompts, verify warnings through official channels, and avoid entering sensitive data into links from unsolicited messages. The core uncertainty now is how thoroughly Brevoโ€™s investigation identifies which organizationsโ€™ contacts were exported versus merely accessed, and whether the attacker obtained broader metadata that could support additional phishing campaigns.

    Crypto firms and their customers should watch for follow-on updates from Brevoโ€™s incident findingsโ€”particularly any clarification on which accounts were used for exports and whether any categories of access overlapโ€”while continuing to educate users to treat โ€œurgent security alertsโ€ sent via newsletter channels as untrusted until verified independently.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Brevo Login Flaw Used To Phish 347k Trezor Users

    Brevo Login Flaw Used to Phish 347K Trezor Users

    3 minutes ago
    Eu Finance Groups Urge Removal Of Cap On Tokenized Securities

    EU Finance Groups Urge Removal of Cap on Tokenized Securities

    2 hours ago
    Liquid Network Restarts Block Production After $320m Exploit

    Liquid Network Restarts Block Production After $320M Exploit

    3 hours ago
    Uk House Of Lords Supports Mandatory Digital Asset Strategy, Beats Labour

    UK House of Lords Supports Mandatory Digital Asset Strategy, Beats Labour

    4 hours ago
    Esma Warns Crypto-Market Linkages May Heighten Risks For Tradfi

    ESMA Warns Crypto-Market Linkages May Heighten Risks for TradFi

    5 hours ago
    Metaplanet Equity Fallout As Se Asia Crypto Funding Doubles

    Metaplanet Equity Fallout as SE Asia Crypto Funding Doubles

    6 hours ago

    Search Crypto News

    Featured Crypto News

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available For Crypto Executives, Investors And Vip Guests

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available for Crypto Executives, Investors and VIP Guests

    7 September 2026

    Latest News

    • Brevo Login Flaw Used to Phish 347K Trezor Users
    • Brevo Login Flaw Linked to Phishing Attacks on 347K Trezor Users
    • EU Finance Groups Urge Removal of Cap on Tokenized Securities
    • Liquid Network Restarts Block Production After $320M Exploit
    • UK House of Lords Supports Mandatory Digital Asset Strategy, Beats Labour
    • ESMA Warns Crypto-Market Linkages May Heighten Risks for TradFi
    • Metaplanet Equity Fallout as SE Asia Crypto Funding Doubles
    • Arya.ag to Store Grain Ownership Records on Avalanche in India
    • Bitcoinโ€™s sell-side pressure slips to rare lows as $80K sellers exit
    • ESMA Flags Rising Crypto Links as a Potential Risk to TradFi

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    eToro Crypto 300x300

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    ๐Ÿ“ž +971 50 449 2025
    โœ‰๏ธ info@cryptobreaking.com
    ๐Ÿ“Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Kraken Pro 300x250
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!