A flaw in Brevo’s login authorization allowed an attacker to access 138 customer accounts and send phishing emails through accounts tied to Trezor, BitBox and CoinTracking, according to the email platform’s postmortem.

The incident let fraudulent messages be distributed through legitimate newsletter infrastructure. Trezor said a fake campaign sent through its Brevo account reached about 347,000 subscribers, and roughly 2,500 people clicked a malicious link before the domain was taken offline.

How the breach worked

Brevo said the attacker abused a weakness tied to its single sign-on system and the way permissions were handled for users connected to more than one organization. The attacker first created a Brevo account, enabled single sign-on, and then invited legitimate Brevo users into that attacker-controlled organization.

Those invited users should only have exposed the new organization created by the attacker. Instead, Brevo said an authorization boundary failed, giving the attacker access to every organization that the invited users were already allowed to use. That is how the incident expanded beyond the attacker’s own account and reached customer environments.

Scale of the incident

Brevo said 138 customer accounts were affected in total. Of those, six were used to send phishing emails, while contacts were exported from 43 accounts. The company also said it saw no meaningful activity across another 93 accounts, though it did not clarify whether those categories overlapped.

The compromised set included accounts used by hardware wallet makers Trezor and BitBox, as well as CoinTracking, which provides crypto portfolio tracking and tax-reporting tools. Because the attacker gained access to real mailing infrastructure, the phishing emails could appear to come from trusted brands rather than from obviously spoofed senders.

What happened to Trezor users

Trezor said its Brevo account stored around 347,000 opt-in newsletter email addresses and no other customer information. The fraudulent message was sent to that entire list before the company issued a warning to subscribers.

According to Trezor, the malicious domain used in the campaign was taken down within 20 minutes, but around 2,500 people had already visited the link by then. The company said the Brevo incident did not compromise Trezor hardware wallets or wallet backups, and added that customers who did not enter their wallet backup into the malicious application remained safe.

Wider phishing risk and next steps

Brevo’s findings indicate the phishing emails were only one part of the attacker’s activity. Since contact lists were exported from 43 accounts, those addresses could potentially be reused in later phishing attempts outside Brevo’s systems.

Trezor said it is treating its full 347,000-address newsletter list as potentially known to the attacker, even though it has not confirmed that all of those addresses were exported. BitBox told users not to follow instructions in fraudulent emails, while CoinTracking reported a phishing lure tied to its own services. For affected users, the main confirmed risk remains follow-on phishing using trusted brand names and previously collected email addresses.

Source: crypto.news