Waltio Users' Email Addresses Compromised in Brevo Breach
Waltio, a French crypto tax platform, has confirmed that it was affected by the recent Brevo breach, which occurred in early September. The company sent an email to its users, informing them of the incident and reassuring them that their tax reports are safe. However, the email addresses associated with their Waltio accounts may have been compromised.
The Brevo breach is believed to have affected around 120-138 customer accounts, including those of prominent crypto companies such as Trezor, BitBox, CoinTracking, and Solana Mobile. In some cases, attackers were able to send phishing emails from legitimate infrastructure, making it difficult for recipients to distinguish between genuine and fake messages.
Trezor was one of the worst affected companies, with approximately 347,000 newsletter subscribers receiving a fake security alert about an STM32 entropy vulnerability. The company quickly took action to block the domain and prevent further damage.
Waltio's notice to its users advises them to take precautions to protect their accounts, including enabling two-factor authentication, reviewing and revoking exchange API keys, and changing their passwords if they have reused them elsewhere. It also suggests that users be cautious of any messages asking for their seed phrase or wallet backup.
The incident serves as a reminder of the importance of security in the crypto industry and the need for companies to prioritize the protection of user data. With the increasing number of data breaches and phishing attacks, it is essential for individuals to stay vigilant and take steps to safeguard their accounts.