By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Brevo Login Flaw Led to Phishing of 347K Trezor Subscribers

A critical login vulnerability within the email marketing platform Brevo facilitated a large-scale phishing attack targeting 347,000 subscribers of Trezor, a manufacturer of cryptocurrency hardware wallets. The breach, disclosed by Trezor on May 22, 2024, allowed attackers to gain unauthorized access to Brevo's system, enabling them to send malicious emails directly to Trezor's customer base. Trezor stated that the phishing emails were sent to 347,000 subscribers and indicated that they are treating every compromised address as "known to the attacker and possibly reusable for phishing." This means that individuals whose email addresses were exposed are at a heightened risk of future targeted attacks.
The incident highlights the interconnectedness of digital services and the cascading security risks that can arise when a single platform's security is compromised. Brevo, formerly known as Sendinblue, is a widely used customer relationship management (CRM) and email marketing service that provides tools for businesses to manage their customer communications, including sending newsletters, transactional emails, and marketing campaigns. Its platform is utilized by numerous companies across various sectors, underscoring the potential reach of such a breach. The compromise of Brevo's login system meant that attackers could impersonate legitimate communications, making it more difficult for recipients to discern between genuine messages and phishing attempts.
Trezor, in its communication, has advised its users to be vigilant and to take immediate steps to secure their accounts. This includes enabling two-factor authentication (2FA) on all online accounts, being wary of unsolicited emails asking for personal information or login credentials, and never clicking on suspicious links or downloading attachments from unknown sources. The company also emphasized the importance of verifying the authenticity of any communication claiming to be from Trezor by directly visiting the official Trezor website rather than relying on links provided in emails. The incident serves as a stark reminder of the persistent threat of phishing attacks, which often exploit vulnerabilities in third-party services to gain access to sensitive customer data.
While the full extent of the compromise and the specific methods used by the attackers are still under investigation, the immediate impact is the exposure of a significant number of Trezor users' email addresses to malicious actors. This exposure increases the likelihood of further targeted attacks, potentially including credential harvesting, malware distribution, and social engineering schemes aimed at tricking users into revealing their private keys or other sensitive cryptocurrency information. The incident underscores the critical need for robust security practices not only for individual users but also for the service providers that handle vast amounts of customer data.
Original source — read the full reporting at the publisher:
Read on CoinTelegraphGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.