Brevo login flaw hit Trezor newsletter subscribers
An attacker used a Brevo login weakness to send phishing emails through client accounts, exposing Trezor’s newsletter list and affecting BitBox and CoinTracking users.
An attacker exploited a weakness in Brevo’s login process to gain access to client accounts and send phishing emails through the platform. The campaign reached about 347,000 subscribers tied to Trezor, while similar messages were also sent from accounts associated with BitBox and CoinTracking.
How the breach worked
Brevo said the attacker first created an account, turned on single sign-on and then invited legitimate Brevo users into that setup. The company said access was supposed to stay limited to that organization, but a failure in the authorization flow allowed the intruder to move further into the system. The result was access to 138 client accounts.
Brevo’s postmortem said six accounts were used to send phishing emails, while contacts were exported from 43 accounts and 93 accounts showed no meaningful activity. The company did not say whether those groups overlapped. That leaves the full scope of the exposure unclear, even though the incident was broad enough to affect several crypto-related businesses.
Impact on Trezor and users
Trezor said the phishing message reached 347,000 newsletter subscribers and that it is treating each address as known to the attacker and potentially reusable for further phishing. That raises the risk that the incident could extend beyond the single email campaign if the stolen data is reused in later attacks.
The hardware wallet maker was not the only affected name. Brevo said the same breach also enabled fraudulent emails linked to BitBox and CoinTracking, showing that the issue spread across multiple customer accounts rather than staying confined to one brand. For users, the main concern is that a trusted mailing channel was abused to deliver the lure.
The episode underlines how attackers can turn business software into a distribution tool for scams. Rather than breaking into end-user wallets directly, the intruder exploited a login and account-authorization weakness at a service provider, then used that access to impersonate familiar brands and reach large mailing lists.
Trezor’s warning means subscribers should be cautious with any message that appears to come from the company, especially if it asks for credentials or pushes urgent action. The incident also adds to pressure on email and customer-relationship platforms to harden account controls, since one breach at the infrastructure layer can quickly spill over to many clients.
This article is not investment advice and recommends no asset, level or direction; a single session's move is not evidence of a trend. For background see Crypto, Altcoin, Bitcoin, and for terms the finance glossary.
Frequently asked questions
What did the attacker use to send the phishing emails?
The attacker used compromised Brevo client accounts after exploiting a flaw in the platform’s login system.
How many Trezor subscribers were affected?
Trezor said the phishing email was sent to 347,000 subscribers.
Which other companies were mentioned in the breach?
Brevo said the campaign also affected accounts linked to BitBox and CoinTracking.
Sources
Related News

Crypto climbs across majors as altcoins lead gains
Bitcoin, ether and the largest altcoins were all higher on Friday, with the day’s moves led by Cardano and XRP. The broader bid left every tracked token in positive territory.

Bitcoin edges lower as altcoins split on Thursday
Crypto traded mixed on Thursday, with ether and cardano edging higher while bitcoin, BNB and XRP fell. The session showed modest dispersion across large-cap tokens rather than a broad directional move.
Crypto theft case: Malone Lam pleads guilty in $245M scheme
Malone Lam has pleaded guilty in a racketeering case tied to the theft and laundering of more than $245 million in crypto through social engineering and break-ins.
Ethereum Outpaces Bitcoin as Network Upgrade Momentum Builds
The second-largest cryptocurrency posted its strongest weekly gain in months ahead of an anticipated network upgrade.
Abu Dhabi royal backs stake in Trump-linked crypto bank
A group linked to Abu Dhabi royal Sheikh Tahnoon bin Zayed Al Nahyan reportedly holds 49% of the company behind World Liberty Financial’s proposed US trust bank.
Solana Network Activity Hits New Highs Amid DeFi Resurgence
Daily transaction counts and total value locked on the network climbed to multi-month peaks as trading activity picked up.