NewsTradingSentimentCalendarCommunityBriefing
Markets

Brevo flaw exposes 347k Trezor users to phishing

By Markets Desk · 2026-09-11 · 1 min read
A digital padlock icon floating above a network of connected nodes
Illustration: Tradingbird

An attacker accessed 138 Brevo client accounts to send phishing emails to 347,000 Trezor subscribers. The breach also affected BitBox and CoinTracking.

A security flaw in the Brevo email platform allowed an attacker to access 138 client accounts. This breach enabled the distribution of phishing emails to 347,000 Trezor newsletter subscribers. The unauthorized access also impacted BitBox and CoinTracking. Trezor reported that approximately 2,500 users clicked the malicious link before the domain was disabled. The company is treating all affected email addresses as compromised.

The attacker created a Brevo account and enabled single sign-on to invite legitimate users. An authorization boundary failure granted access to every organization those users could reach. Brevo stated that six accounts were used to send phishing emails. Contacts were exported from 43 accounts. The platform noted that 93 accounts showed no meaningful activity. Brevo did not specify if these categories overlapped.

Trezor disables malicious domain quickly

Trezor identified the phishing email as a fake security alert. The message requested users to provide wallet backups. The company disabled the malicious domain at the DNS level within 20 minutes. A Trezor spokesperson confirmed the initial email reached 347,000 customers. All recipients were contacted regarding the risk. The Brevo account held only opt-in newsletter addresses. No other customer data was stored in that specific account.

BitBox and CoinTracking confirm exposure

BitBox stated its unauthorized email reached its full newsletter list. The company found no evidence of compromised credentials. BitBox reported no lost funds or disclosed recovery phrases. The firm is treating the list as potentially accessed. CoinTracking distributed an email titled Data Breach Notice. The message urged recipients to refresh API keys. CoinTracking warned users not to follow the email links.

Brevo explains authorization boundary failure

Brevo issued a postmortem on Thursday regarding the incident. The company said access should have been confined to the attacker’s organization. The failure allowed access to all reachable organizations. Cointelegraph reached out to Brevo for additional information. The company did not respond before publication. The disclosure expands on warnings from Trezor and BitBox. It explains why the emails passed authentication checks.

Based on reporting by Cointelegraph, compiled by the Tradingbird desk.

More from the Markets desk

All desk stories