About 347,000 Trezor customers received phishing emails after attackers broke into Brevo, the marketing platform the hardware wallet maker uses for newsletters.
According to Brevo, the intrusion hinged on its SAML single sign-on handling. The sequence was straightforward: set up a Brevo account, turn SSO on, and invite genuine Brevo users in. Because those users authenticate via their own identity provider, the attacker could impersonate them, which is the normal SSO path working as designed. The problem was scope: instead of access limited to one organization, the flaw granted reach into every organization those users could touch.
Across 138 accounts touched, the attacker pulled contacts from 43 and sent phishing mail from six. Trezor customers received mail titled “Critical Security Alert: STM32 Entropy Vulnerability” pointing to a malicious site. Trezor warned customers that entering a wallet backup after clicking could cost them their funds.
The takedown came 20 minutes after detection, by which point some 2,500 people had clicked. It is unclear whether anyone lost crypto.
Swiss wallet maker BitBox and crypto tax tool CoinTracking look to have been pulled into the same campaign, though neither has named Brevo.
The Brevo incident lands less than a month after a breach at Trezor’s shipping provider ShipMonk exposed data on roughly 14,000 people, later revised to add 67,000 more US customers.
