Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Hackers compromised the Brevo marketing platform by exploiting its SAML Single Sign-On (SSO) implementation, gaining unauthorized access to multiple customer accounts. Using this access, attackers sent phishing emails to approximately 347,000 Trezor users, among others, with malicious links designed to steal wallet backups. About 2,500 users clicked the phishing link before the malicious site was taken offline. The incident also involved exfiltration of contact data from 43 Brevo accounts. Other affected customers include BitBox and CoinTracking. This breach follows a recent data leak involving Trezor's third-party shipping provider, increasing the risk of targeted phishing attacks.
AI Analysis
Technical Summary
The Brevo marketing platform was compromised through an SSO misconfiguration that allowed an attacker to access 138 accounts across multiple organizations. The attacker created a Brevo account, enabled SSO, and invited legitimate users, then used their own identity provider to sign in as those users. Due to improper scoping, the attacker gained access to all organizations accessible by those users, not just the intended single organization. The attacker sent phishing emails containing a malicious link to email addresses stored in six compromised accounts, including Trezor's, affecting roughly 347,000 users. The phishing emails warned of a 'Critical Security Alert: STM32 Entropy Vulnerability' and aimed to steal wallet backups. The malicious site was taken down within 20 minutes after detection. Additionally, contact data was exfiltrated from 43 accounts. BitBox and CoinTracking were also impacted, though details remain sparse. This incident compounds risks for Trezor users following a recent data breach at its shipping provider ShipMonk.
Potential Impact
The phishing campaign targeted hundreds of thousands of cryptocurrency hardware wallet users, potentially exposing them to theft of wallet backups and loss of funds. Approximately 2,500 users clicked the malicious link before the site was taken offline, though the exact extent of financial loss is unknown. The breach also exposed contact data from multiple organizations, increasing the risk of further phishing or social engineering attacks. The incident undermines user trust in affected companies and highlights risks from third-party service compromises.
Mitigation Recommendations
No official patch applies as this is a compromise of a third-party marketing platform and not a software vulnerability. Brevo has taken down the malicious website and addressed the SSO misconfiguration. Affected organizations should notify users promptly about the phishing campaign and advise them not to click suspicious links or enter wallet backups on untrusted sites. Users should verify communications through official channels and consider additional security measures such as hardware wallet PINs and passphrases. Monitoring for further phishing attempts is recommended. Since this is a third-party breach, remediation depends on Brevo and affected customers' response.
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Description
Hackers compromised the Brevo marketing platform by exploiting its SAML Single Sign-On (SSO) implementation, gaining unauthorized access to multiple customer accounts. Using this access, attackers sent phishing emails to approximately 347,000 Trezor users, among others, with malicious links designed to steal wallet backups. About 2,500 users clicked the phishing link before the malicious site was taken offline. The incident also involved exfiltration of contact data from 43 Brevo accounts. Other affected customers include BitBox and CoinTracking. This breach follows a recent data leak involving Trezor's third-party shipping provider, increasing the risk of targeted phishing attacks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Brevo marketing platform was compromised through an SSO misconfiguration that allowed an attacker to access 138 accounts across multiple organizations. The attacker created a Brevo account, enabled SSO, and invited legitimate users, then used their own identity provider to sign in as those users. Due to improper scoping, the attacker gained access to all organizations accessible by those users, not just the intended single organization. The attacker sent phishing emails containing a malicious link to email addresses stored in six compromised accounts, including Trezor's, affecting roughly 347,000 users. The phishing emails warned of a 'Critical Security Alert: STM32 Entropy Vulnerability' and aimed to steal wallet backups. The malicious site was taken down within 20 minutes after detection. Additionally, contact data was exfiltrated from 43 accounts. BitBox and CoinTracking were also impacted, though details remain sparse. This incident compounds risks for Trezor users following a recent data breach at its shipping provider ShipMonk.
Potential Impact
The phishing campaign targeted hundreds of thousands of cryptocurrency hardware wallet users, potentially exposing them to theft of wallet backups and loss of funds. Approximately 2,500 users clicked the malicious link before the site was taken offline, though the exact extent of financial loss is unknown. The breach also exposed contact data from multiple organizations, increasing the risk of further phishing or social engineering attacks. The incident undermines user trust in affected companies and highlights risks from third-party service compromises.
Defensive Guidance
No official patch applies as this is a compromise of a third-party marketing platform and not a software vulnerability. Brevo has taken down the malicious website and addressed the SSO misconfiguration. Affected organizations should notify users promptly about the phishing campaign and advise them not to click suspicious links or enter wallet backups on untrusted sites. Users should verify communications through official channels and consider additional security measures such as hardware wallet PINs and passphrases. Monitoring for further phishing attempts is recommended. Since this is a third-party breach, remediation depends on Brevo and affected customers' response.
Technical Details
- Classification
- {"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/","fetched":true,"fetchedAt":"2026-09-11T13:01:57.533Z","wordCount":1118}
Threat ID: 6aa3fbc591cc7f38482f120d
Added to database: 09/11/2026, 13:01:57 UTC
Last enriched: 09/11/2026, 13:02:13 UTC
Last updated: 09/11/2026, 15:16:20 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.