Brevo Email Provider Breach Exposes Thousands to Phishing Scams
Thousands of cryptocurrency holders received phishing emails on Wednesday after hackers breached an email provider and sent out corrupted messages. The emails appeared to come from reputable companies such as Trezor, CoinTracking, and BitBox, and contained links that led to phishing websites nearly identical to the legitimate platforms.
CoinTracking confirmed that the breach occurred at Brevo, an email service provider, which released a statement warning that an attacker had access to 120 customer accounts. The company claimed that the hackers used the login information of legitimate users and expanded their access through a vulnerability in the system.
The attack resulted in 138 Brevo accounts being breached, with six of those accounts used to send phishing emails to contacts stored there. In total, 43 accounts had their contacts exported by the attackers.