Urgent.News

What's breaking now, across thousands of outlets.

Tech

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

Trezor told Cointelegraph that the phishing email was sent to 347,000 subscribers and said it is treating every address as “known to the attacker and possibly reusable for phishing.”

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

The phishing email targeted 347,000 Trezor subscribers after an attacker exploited a flaw in email platform Brevo's login system. Brevo's postmortem revealed that six accounts were used to send phishing emails, with contacts exported from 43 and 93 accounts showing no meaningful activity. Trezor and BitBox, two hardware wallet providers, warned their users about the vulnerability on Wednesday, explaining how the emails managed to pass normal authentication checks and appear genuine.

The phishing email, titled "Critical Security Alert: STM32 Entropy Vulnerability," contained a link to an app requesting users' wallet backups. Trezor disabled the domain at the DNS level within 20 minutes, but more than 2,500 people accessed the link before its removal. Trezor's spokesperson confirmed that the initial email was sent to all 347,000 customers and emphasized that they are treating all of these addresses as known to the attacker and potentially reusable for phishing.

BitBox stated that their unauthorized email was sent through Brevo and reached its full newsletter and tutorial list, but found no evidence of compromised company credentials or loss of funds. CoinTracking also reported that its Brevo account distributed an email warning recipients not to follow any links.

Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at cointelegraph.com →

More in Tech

The Retry That Restored Access

Retries keep distributed systems moving through timeouts and temporary failures. In an access system, though, an old retry can be more dangerous than a failed request.

More from Friday 11 September →