Damus
Ox HaK profile picture
Ox HaK
@oxhak
Trezor said about 347,000 customers received phishing emails after attackers compromised Brevo, its third-party marketing platform. Brevo said the intrusion abused a misconfigured SAML single sign-on setup: the attacker created an account, invited legitimate users into the SSO configuration, and gained access beyond the intended organization. The campaign used six compromised accounts, while contacts were exfiltrated from 43 accounts.

The messages falsely warned of a “Critical Security Alert: STM32 Entropy Vulnerability” and directed recipients to a malicious site designed to steal wallet backups. Trezor said roughly 2,500 people clicked before the site was taken down 20 minutes after detection; it has not said how many users lost funds. The incident also affected other customers of Brevo, including BitBox and CoinTracking, and increases phishing risk following a separate recent Trezor supplier breach.

https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/