Trezor Users Affected by Phishing Emails Following Brevo Marketing Platform Hack
Cold cryptocurrency storage provider Trezor has announced that approximately 347,000 of its customers received phishing emails due to a security breach at Brevo, a third-party marketing platform used by Trezor for newsletters. Brevo confirmed that an attacker exploited a vulnerability in its handling of SAML Single Sign-On (SSO) to gain unauthorized access to 138 accounts. The attacker created a Brevo account, enabled SSO, and then invited legitimate Brevo users into that SSO configuration. This allowed the attacker to sign in as those invited users, and critically, this access was not properly scoped, granting the attacker access to all organizations those users could reach, not just the single organization where SSO was enabled. The attacker subsequently sent phishing messages to email addresses stored under six compromised accounts and exfiltrated contacts from 43 accounts. The phishing emails, with the subject line 'Critical Security Alert: STM32 Entropy Vulnerability,' contained a malicious link. Trez...