Brevo Login Breach Leads to Phishing Emails Sent to 347,000 Trezor Subscribers, BitBox and CoinTracking Accounts Also Affected
Odaily News: A vulnerability in email platform Brevo's login system allowed attackers to access 138 customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. Accounts belonging to BitBox and cryptocurrency portfolio and tax reporting platform CoinTracking were also used to send similar scam emails.
Trezor stated that the phishing email was titled "Critical Security Alert: STM32 Entropy Vulnerability," with links pointing to an app that asked users to submit their wallet backups. Trezor disabled the relevant domain via DNS within 20 minutes, but approximately 2,500 people had visited the link, and the company has alerted all 347,000 subscribers to the risk.
Brevo stated that attackers exploited a failure in single sign-on configuration permission boundaries to access all organizations reachable by invited users. Six accounts were used to send phishing emails, and contact data from 43 accounts was exported. BitBox and CoinTracking said they have found no evidence of leaked company credentials, funds, or recovery phrases, but are treating the affected email addresses as potentially compromised. (Cointelegraph)
