Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Attackers abused Brevo's SAML SSO to access 138 accounts, sending phishing emails to 347,000 Trezor customers and exfiltrating contacts from 43 accounts.
Trezor said 347,000 of its customers received phishing emails with the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' after the attacker compromised the Brevo marketing platform. Brevo said the intruder created an account, enabled SAML SSO, and used its own identity provider to access 138 accounts, exfiltrating contacts from 43 of them. Trezor reported 2,500 users clicked the malicious link before the site was taken offline 20 minutes after detection; potential fund losses are unknown. Swiss wallet maker BitBox and crypto tax calculator CoinTracking also appear affected, and Trezor separately disclosed a ShipMonk breach now affecting roughly 81,000 people.