Fri. Sep 11th, 2026

Brevo Breach Expands to 138 Accounts as Crypto Firms Face Phishing Fallout

ByShane Neagle

September 11, 2026 #Brevo
Crypto Hack

Trezor, BitBox and CoinTracking Caught in Wider Email Provider Compromise

The security incident behind this week’s Trezor phishing campaign was substantially broader than initially known, with email marketing provider Brevo confirming that an attacker gained access to 138 customer accounts through a flaw in its single sign-on system.

Brevo said it identified the security issue at 6:30 a.m. UTC on Sept. 10. Of the 138 accessed accounts, six were used to send phishing emails, contacts were exported from 43 accounts and 93 showed no meaningful attacker activity. Brevo did not clarify whether those categories overlap.

The attack did not begin with stolen passwords from individual Brevo customers. According to Brevo’s postmortem, the attacker created a Brevo account, enabled SAML single sign-on and invited legitimate Brevo users into that SSO configuration.

The critical failure occurred at the authorization boundary. Once the attacker authenticated as one of the invited users through its own identity provider, Brevo’s system should have limited that login to the organization where the SSO configuration had been created. Instead, the attacker was incorrectly granted access to every Brevo organization that those users could access.

Brevo closed the access route at 8:30 a.m. UTC on Sept. 10, approximately two hours after identifying the incident, and forcibly signed out every active user on the platform. The company said it has seen no further attacker activity since then and is deploying a permanent change restricting SSO sessions to the organization that owns the relevant configuration.

The new disclosure turns what initially appeared to be a phishing incident involving hardware wallet maker Trezor into a wider third-party infrastructure compromise affecting multiple crypto companies.

Trezor said approximately 347,000 opt-in newsletter subscribers received a fraudulent email titled “Critical Security Alert: STM32 Entropy Vulnerability.” The message directed recipients to a malicious application that attempted to persuade them to enter their wallet backup.

The wallet maker took down the malicious domain at the DNS level within about 20 minutes, but around 2,500 recipients had already clicked the link by then. Trezor said clicking alone did not put funds at risk; the danger arose for anyone who subsequently entered a wallet backup into the malicious application or another online form.

Trezor’s Brevo database contained newsletter email addresses rather than wallet credentials, passwords or wallet information. However, the company said it cannot yet confirm whether its subscriber list was among those exported and is therefore treating all roughly 347,000 email addresses as potentially known to the attacker and reusable in future phishing campaigns.

Hardware wallet maker BitBox was also targeted through Brevo. Its fraudulent email appears to have reached the company’s full newsletter and tutorial mailing list. BitBox said its Brevo data consisted of email addresses and language preferences and that it had found no evidence that company credentials were compromised or its contact database downloaded. It nevertheless is treating the subscriber list as potentially exposed while awaiting additional Brevo logs.

Crypto portfolio and tax-reporting platform CoinTracking experienced a similar attack. Customers received an unauthorized message titled “Data Breach Notice: Please refresh API Keys as soon as possible,” attempting to steer them toward links where login information or exchange API credentials could potentially be captured. CoinTracking warned customers who entered exchange API keys to revoke them directly at the relevant exchange and generate replacements.

The Brevo flaw made the phishing particularly difficult to identify using normal email checks. The company acknowledged that the fraudulent campaigns were sent through legitimate customer infrastructure, meaning they passed ordinary email authentication mechanisms and could appear to recipients as genuine company communications.

Brevo has not publicly identified the remaining affected customers. The company says it is contacting each impacted organization directly with account-specific information.

That leaves open the possibility of further disclosures. Only a handful of the 138 accessed Brevo accounts have so far been publicly connected to the incident, while 43 accounts experienced contact exports according to Brevo’s investigation.

The scale of Brevo itself makes that unanswered question more significant. The Paris-based customer relationship and marketing platform says it serves about 600,000 customers globally across email marketing, transactional messaging, CRM and other communications products.

For Trezor, the Brevo incident also follows another major third-party data exposure. Shipping provider ShipMonk disclosed a breach in August that ultimately affected approximately 80,689 Trezor customers, including some records containing names, phone numbers, email addresses and physical shipping addresses. Trezor said its own systems were not compromised in that incident either.

The latest breach therefore highlights a recurring problem for crypto firms: highly secured wallets and internal systems can remain untouched while attackers exploit the external services used to communicate with the customers who hold the assets.

The Most Dangerous Part Was That the Emails Were Real

There is an important difference between spoofing a company and actually sending a malicious message through the infrastructure that company legitimately uses.

Most phishing education starts with the same advice: inspect the sender, look for suspicious domains, check whether an email passes authentication and avoid obvious impersonators.

The Brevo attack weakened several of those defenses at once.

The attacker did not merely imitate Trezor, BitBox or CoinTracking. Once access to their Brevo environments was obtained, malicious messages could be distributed through infrastructure already authorized to communicate on their behalf. Brevo itself acknowledges that the emails passed normal authentication checks.

For a recipient, that changes the problem considerably.

An email can come through the expected delivery system, use the company’s branding, reach exactly the audience that normally receives its newsletters and still be malicious. In that situation, “check whether the sender looks legitimate” is no longer enough.

That is especially dangerous in crypto because the audiences stored inside these systems are unusually valuable.

A generic leaked email address has some value to a scammer. An email address known to subscribe to Trezor communications tells an attacker something much more useful: this person is more likely than the general population to own cryptocurrency and potentially use a hardware wallet.

The first phishing campaign may therefore be only one stage of the incident.

Even if no further messages can be sent through Brevo, an exported newsletter list can be reused months later. Attackers can impersonate wallet upgrades, firmware alerts, exchange notices, regulatory requirements or support representatives. Those later messages no longer need access to Brevo because the attacker already knows whom to target.

This is why Trezor’s decision to treat all 347,000 subscribers as potentially exposed matters even though it has not confirmed that its list was among the 43 exports.

The broader Brevo figures create another unanswered issue. Six accounts were actively weaponized for phishing, but contact lists were exported from 43. That means the visible phishing campaigns may represent only part of the useful data the attacker obtained.

And only Trezor, BitBox and CoinTracking have so far emerged publicly as crypto-related victims.

If other exchanges, wallet providers, brokers or financial platforms are among the remaining Brevo customers affected, they may face the same problem without their users yet knowing that a trusted marketing database was accessed.

There is also a vendor-risk lesson here that extends beyond Brevo.

Crypto companies spend enormous amounts of effort securing private keys, wallet firmware, signing infrastructure and internal access. Yet customer relationships inevitably pass through ordinary SaaS products: email providers, support desks, analytics platforms, CRM systems and shipping companies.

Those services do not custody the crypto, but they custody something attackers increasingly need almost as much — the identity and attention of the person who does.

Brevo’s SSO flaw therefore did not need to compromise a hardware wallet to create a meaningful wallet-security threat. It only had to give attackers the ability to speak convincingly, and legitimately, to hundreds of thousands of people who use one.

Financial Markets Analyst and Digital Assets Journalist at  |  More Posts

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.

He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.

Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *