ADVERTISEMENT
LIVE DESK·Global markets desk·Last updated 14s ago
ADVERTISEMENT
Markets/CryptoArticle

Brevo login flaw enabled phishing to 347,000 Trezor subscribers

Brevo said an authorization failure let an attacker access 138 client accounts and send phishing emails to about 347,000 Trezor subscribers, with similar messages sent via BitBox and CoinTracking.

MW
Marcus Webb · Crypto Desk · 11 Sept 2026 · 06:27 · 2 min read
Share
Brevo login flaw enabled phishing to 347,000 Trezor subscribers

An attacker exploited a flaw in Brevo's login and authorization system to access 138 client accounts, according to a postmortem published by the email platform on Thursday. The breach enabled phishing emails to reach roughly 347,000 subscribers of Trezor, while similar fraudulent messages were distributed through accounts belonging to BitBox, a hardware wallet maker, and CoinTracking, a crypto portfolio tracking and tax-reporting platform.

Brevo said six accounts were used to send phishing emails, contacts were exported from 43 accounts, and 93 accounts showed no meaningful activity. It did not say whether the groups overlapped. The company said the attacker created a Brevo account, enabled single sign-on and invited legitimate users into the configuration. Access should have been limited to that organization, but an authorization boundary failed and gave the attacker access to every organization the invited users could reach.

The disclosure expanded on warnings issued by Trezor and BitBox on Wednesday and explained why the messages passed normal authentication checks and appeared genuine. Brevo did not respond to a request for comment before publication.

Bitcoin

BTCUSD
Full profile →
77364.9300▲ 1.04%
As of 11/09/2026, 00:00:00

Trezor said the phishing message, titled "Critical Security Alert: STM32 Entropy Vulnerability," contained a link to an app that requested users' wallet backups. The company said it disabled the domain at the DNS level within 20 minutes, but about 2,500 people accessed the link before the takedown. A Trezor spokesperson said the initial email was sent to 347,000 customers and that all recipients were subsequently contacted about the risk. The company's Brevo account stored only opt-in newsletter email addresses and no other customer data. The company said it was treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing until it received more information from Brevo.

A BitBox spokesperson said its unauthorized email was sent through Brevo and appeared to have reached its full newsletter and tutorial list. The company said Brevo held only email addresses and language preferences. BitBox said it found no evidence of compromised company credentials, downloaded contacts, lost funds or disclosed recovery phrases, but it is treating the list as potentially accessed while awaiting Brevo's logs.

CoinTracking said its Brevo account distributed an email titled "Data Breach Notice: Please refresh API Keys as soon as possible." The company warned recipients not to follow the email's links.

This article was produced with AI assistance and edited by a Finance Review Daily journalist.
ADVERTISEMENT
Share this story
MW
Written by
Marcus Webb
Crypto Desk

Marcus reports on digital assets, from spot ETF flows to protocol-level developments in DeFi. He pays particular attention to how institutional adoption is reshaping crypto market structure.

More from Marcus Webb →
ADVERTISEMENT
ADVERTISEMENT
Brevo login flaw hit 347,000 Trezor subscribers · Finance Review Daily