Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

Summary

Brevo disclosed an authorization flaw in its login/SSO system that let an attacker access 138 client accounts and use several of them to send phishing emails. The abuse affected crypto-related customers including Trezor, BitBox, and CoinTracking. Brevo said six accounts were used to send phishing, contacts were exported from 43 accounts, and 93 showed no meaningful activity. The attack began when the attacker created a Brevo account, enabled single sign-on, and invited legitimate users. A boundary failure then exposed other organizations those users could reach. Trezor said a fake “Critical Security Alert” email reached about 347,000 newsletter subscribers; roughly 2,500 clicked before the domain was disabled. BitBox and CoinTracking also reported fraudulent emails sent through Brevo. The companies said Brevo accounts stored only email lists and basic preferences, with no evidence yet of lost funds or compromised wallet data.