An attacker exploited a flaw in Brevo's login and authorization system to access 138 client accounts, according to a postmortem published by the email platform on Thursday. The breach enabled phishing emails to reach roughly 347,000 subscribers of Trezor, while similar fraudulent messages were distributed through accounts belonging to BitBox, a hardware wallet maker, and CoinTracking, a crypto portfolio tracking and tax-reporting platform.
Brevo said six accounts were used to send phishing emails, contacts were exported from 43 accounts, and 93 accounts showed no meaningful activity. It did not say whether the groups overlapped. The company said the attacker created a Brevo account, enabled single sign-on and invited legitimate users into the configuration. Access should have been limited to that organization, but an authorization boundary failed and gave the attacker access to every organization the invited users could reach.
The disclosure expanded on warnings issued by Trezor and BitBox on Wednesday and explained why the messages passed normal authentication checks and appeared genuine. Brevo did not respond to a request for comment before publication.
Trezor said the phishing message, titled "Critical Security Alert: STM32 Entropy Vulnerability," contained a link to an app that requested users' wallet backups. The company said it disabled the domain at the DNS level within 20 minutes, but about 2,500 people accessed the link before the takedown. A Trezor spokesperson said the initial email was sent to 347,000 customers and that all recipients were subsequently contacted about the risk. The company's Brevo account stored only opt-in newsletter email addresses and no other customer data. The company said it was treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing until it received more information from Brevo.
A BitBox spokesperson said its unauthorized email was sent through Brevo and appeared to have reached its full newsletter and tutorial list. The company said Brevo held only email addresses and language preferences. BitBox said it found no evidence of compromised company credentials, downloaded contacts, lost funds or disclosed recovery phrases, but it is treating the list as potentially accessed while awaiting Brevo's logs.
CoinTracking said its Brevo account distributed an email titled "Data Breach Notice: Please refresh API Keys as soon as possible." The company warned recipients not to follow the email's links.













