Brevo Login Flaw Exposes Hundreds of Thousands to Phishing
An attacker exploited a flaw in Brevo's login system to access 138 client accounts, enabling a phishing email to reach roughly 347,000 Trezor newsletter subscribers and similar fraudulent messages to be distributed through accounts belonging to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking.
The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into the configuration. Despite access being confined to that organization, an authorization boundary failed and granted access to every organization the invited users could reach.
Trezor said the phishing message contained a link to an app that requested users' wallet backups. The company disabled the domain at the DNS level within 20 minutes, but about 2,500 people accessed the link before the takedown. Trezor is treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing.
BitBox said its unauthorized email was sent through Brevo and appeared to have reached its full newsletter and tutorial list. CoinTracking also reported that its Brevo account distributed an email warning recipients not to follow links in a potential data breach notice.