Brevo Flaw Exposes Crypto Newsletter Subscribers to Phishing Attacks
A security flaw in Brevo's email login setup allowed an attacker to access client accounts and launch phishing campaigns that targeted subscribers of multiple crypto companies, including Trezor. According to Brevo's post-incident write-up, 138 client accounts were involved, with phishing messages sent through infrastructure connected to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking.
The incident highlights how widely used marketing and notification providers can become a bridge for account-based compromise, one that can bypass typical email authentication safeguards and reach audiences that expect legitimate updates. Trezor reported that the initial phishing email was sent to roughly 347,000 newsletter customers, and it disabled the malicious domain within about 20 minutes.
Trezor, BitBox, and CoinTracking share the same email provider for newsletters, which enabled the attacker to pivot across multiple crypto audiences. Brevo said an intended authorization boundary failed, allowing access beyond the organization where invited Brevo users belonged. Crypto firms are treating their affected newsletter lists as potentially exposed and possibly reusable for further phishing attempts until more details emerge.