RUECAT DEX
All news
Cointelegraph 4h ago

Brevo Login Flaw Exploited to Launch Phishing Campaign Against 347,000 Trezor Subscribers

A security breach at email provider Brevo allowed attackers to blast targeted phishing emails to 347,000 Trezor newsletter subscribers.

Glowing cybersecurity warning icon depicting the aftermath of a Trezor phishing attack breach.

Hardware wallet manufacturer Trezor has issued an urgent security warning following a major Trezor phishing attack that leveraged an unauthorized intrusion at third-party marketing platform Brevo. The security incident allowed malicious actors to dispatch unauthorized emails to hundreds of thousands of newsletter subscribers, attempting to deceive users into compromising their recovery seeds.

According to Cointelegraph, Trezor confirmed that the unauthorized phishing message reached approximately 347,000 registered email subscribers. In response to the breach, the hardware security company announced that it is now treating every single affected email address as permanently exposed and potentially subject to follow-up social engineering campaigns by cybercriminals.

The attack unfolded when perpetrators exploited an authentication vulnerability within Brevo, the enterprise email service provider utilized by Trezor for customer outreach. By hijacking authenticated access, the attackers bypassed standard domain validation defenses, allowing fraudulent emails to appear completely legitimate in recipients' inboxes and evading common spam filters.

Security specialists emphasized that while the attacker gained unauthorized access to marketing contact lists, Trezor's underlying hardware devices, firmware architecture, and private key storage mechanisms remained entirely uncompromised. Nevertheless, phishing campaigns targeting non-technical cryptocurrency holders represent a persistent threat, as attackers seek to trick users into typing recovery seed phrases into cloned websites.

The incident underscores the recurring supply-chain vulnerabilities associated with integrating third-party marketing and communication vendors in the cryptocurrency sector. Industry participants face growing pressure to implement strict zero-trust architectures and minimize the amount of customer data shared with external service providers to prevent similar breaches.

Moving forward, Trezor is advising all customers to maintain strict security hygiene, ignore unsolicited emails requesting seed phrase inputs, and verify all official communications through authenticated channels. Cybersecurity investigators will continue auditing the incident alongside Brevo to ensure that the initial entry vector has been fully sealed against future intrusion attempts.

Key takeaways

  • A vulnerability in email provider Brevo allowed attackers to email 347,000 Trezor subscribers.
  • Trezor's hardware devices and firmware were not breached, but contact emails were compromised.
  • The company is treating all targeted email addresses as permanently exposed to phishing risks.
Source: Cointelegraph