A flaw in Brevo’s email login setup allowed an attacker to access client accounts and launch phishing campaigns that targeted subscribers of multiple crypto companies, including Trezor. Brevo’s post-incident write-up says 138 client accounts were involved, with phishing messages sent through infrastructure connected to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking.
The incident matters for users because it highlights how widely used marketing and notification providers can become a bridge for account-based compromise—one that can bypass typical email authentication safeguards and reach audiences that expect legitimate updates.
Key takeaways
- Brevo said an attacker used a login-system issue to gain access to 138 client accounts and send phishing emails from six of them.
- Trezor reported that the initial phishing email was sent to roughly 347,000 newsletter customers, and it disabled the malicious domain within about 20 minutes.
- Trezor, BitBox, and CoinTracking share the same email provider for newsletters, which enabled the attacker to pivot across multiple crypto audiences.
- Brevo said an intended authorization boundary failed, allowing access beyond the organization where invited Brevo users belonged.
- Crypto firms are treating their affected newsletter lists as potentially exposed and possibly reusable for further phishing attempts until more details emerge.
Brevo’s incident report: authorization boundary failure
In a Thursday postmortem, Brevo described how the attacker exploited a vulnerability in its login system to reach other organizations. Brevo said six accounts were used to send phishing emails. It also reported that contacts were exported from 43 accounts, while 93 accounts showed no meaningful activity. The company did not clarify whether those categories overlapped.
According to Brevo’s write-up, the attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into the configuration. Brevo said access should have been confined to a single organization, but the authorization boundary failed—granting the attacker access to every organization the invited users could reach.
Brevo also published its incident details through its status page, including the write-up referenced by affected companies.
Why crypto newsletters looked legitimate
The scope of the phishing effort expanded on earlier warnings from Trezor and BitBox, which had flagged that their shared email provider could be used to deliver convincing messages. Earlier coverage from Cointelegraph noted how the attack was able to pass normal authentication checks and appear genuine to recipients.
That combination—credible branding plus delivery through a familiar provider—makes these campaigns especially dangerous. Users are more likely to trust emails that match the expected tone and format of official newsletters, even when the link or call-to-action is malicious.
Trezor: app request tied to wallet backups
In a separate blog post, Trezor detailed what it said the phishing message contained. The email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” included a link to an app that asked users for their wallet backups.
Trezor said it disabled the domain at the DNS level within 20 minutes. Even so, it reported that roughly 2,500 people accessed the link before the takedown.
A Trezor spokesperson told Cointelegraph that the initial email was sent to 347,000 customers and that all of those newsletter subscribers were later contacted about the risk. The company said its Brevo account stored only opt-in newsletter email addresses and no other customer data.
Until additional information is provided by Brevo, the spokesperson added that Trezor is treating the roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for future phishing.
BitBox and CoinTracking: lists potentially exposed
BitBox said its unauthorized email was sent through Brevo and appeared to reach its full newsletter and tutorial list. In comments relayed to Cointelegraph, a BitBox spokesperson said the Brevo account stored only email addresses and language preferences.
BitBox reported that it found no evidence of compromised company credentials, did not observe downloads of contacts beyond what would be expected in normal operations, and saw no signs of lost funds or disclosure of recovery phrases. However, it said it is treating the newsletter list as potentially accessed while it awaits Brevo’s logs.
CoinTracking, meanwhile, said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” CoinTracking told recipients not to follow the email’s links.
Taken together, these responses underscore a common pattern: even when companies confirm that no funds were taken and no secret keys or recovery phrases were released, the exposure of email addresses and the ability to reach subscribers can still provide a platform for repeated social engineering.
What to watch next: breach scope and future targeting
Brevo’s report indicates that the attack relied on a failure in access controls tied to single sign-on invitations, but the company’s account-by-account impact remains partially detailed. Readers should watch for additional confirmation of which customer lists were actually exported or contacted, and whether attackers can reuse the exposed addresses for follow-on campaigns.






