<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Trezor Users Hit by Phishing After Brevo Platform Hack

Brevo's SSO flaw exposed 138 accounts, and BitBox and CoinTracking were caught in it too. The emails passed every authentication check.
Content Team

A phishing campaign reached roughly 347,000 Trezor customers after an attacker got into Brevo, the marketing platform Trezor uses for newsletters. Brevo says the attacker reached 138 accounts, sent phishing from six, and exported contacts from 43, with BitBox and CoinTracking users apparently hit as well.

The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into that configuration, then signed in as them through their own identity provider. That access was never scoped to one organization, so it reached every organization those users could see. Brevo closed the route two hours after spotting it, signed out every user, and disabled the links.

Because the emails left real Brevo infrastructure, they passed the usual authentication checks. Trezor's carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and pointed at a site set up to harvest wallet backups. Around 2,500 people clicked in the 20 minutes before Trezor caught it.

It is Trezor's second third-party failure in a month, after a breach at shipping provider ShipMonk exposed nearly 14,000 people, plus another 67,000 US customers disclosed on September 4.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo