Skip to main content

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

0
High
Phishingphishing
Published: 09/11/2026 (09/11/2026, 12:48:04 UTC)
Source: SecurityWeek

Description

Hackers compromised the Brevo marketing platform by exploiting its SAML Single Sign-On (SSO) implementation, gaining unauthorized access to multiple customer accounts. Using this access, attackers sent phishing emails to approximately 347,000 Trezor users, among others, with malicious links designed to steal wallet backups. About 2,500 users clicked the phishing link before the malicious site was taken offline. The incident also involved exfiltration of contact data from 43 Brevo accounts. Other affected customers include BitBox and CoinTracking. This breach follows a recent data leak involving Trezor's third-party shipping provider, increasing the risk of targeted phishing attacks.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 13:02:13 UTC

Technical Analysis

The Brevo marketing platform was compromised through an SSO misconfiguration that allowed an attacker to access 138 accounts across multiple organizations. The attacker created a Brevo account, enabled SSO, and invited legitimate users, then used their own identity provider to sign in as those users. Due to improper scoping, the attacker gained access to all organizations accessible by those users, not just the intended single organization. The attacker sent phishing emails containing a malicious link to email addresses stored in six compromised accounts, including Trezor's, affecting roughly 347,000 users. The phishing emails warned of a 'Critical Security Alert: STM32 Entropy Vulnerability' and aimed to steal wallet backups. The malicious site was taken down within 20 minutes after detection. Additionally, contact data was exfiltrated from 43 accounts. BitBox and CoinTracking were also impacted, though details remain sparse. This incident compounds risks for Trezor users following a recent data breach at its shipping provider ShipMonk.

Potential Impact

The phishing campaign targeted hundreds of thousands of cryptocurrency hardware wallet users, potentially exposing them to theft of wallet backups and loss of funds. Approximately 2,500 users clicked the malicious link before the site was taken offline, though the exact extent of financial loss is unknown. The breach also exposed contact data from multiple organizations, increasing the risk of further phishing or social engineering attacks. The incident undermines user trust in affected companies and highlights risks from third-party service compromises.

Defensive Guidance

No official patch applies as this is a compromise of a third-party marketing platform and not a software vulnerability. Brevo has taken down the malicious website and addressed the SSO misconfiguration. Affected organizations should notify users promptly about the phishing campaign and advise them not to click suspicious links or enter wallet backups on untrusted sites. Users should verify communications through official channels and consider additional security measures such as hardware wallet PINs and passphrases. Monitoring for further phishing attempts is recommended. Since this is a third-party breach, remediation depends on Brevo and affected customers' response.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/","fetched":true,"fetchedAt":"2026-09-11T13:01:57.533Z","wordCount":1118}

Threat ID: 6aa3fbc591cc7f38482f120d

Added to database: 09/11/2026, 13:01:57 UTC

Last enriched: 09/11/2026, 13:02:13 UTC

Last updated: 09/11/2026, 15:16:20 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses