Trezor Phishing Hack: 347,000 Users Affected After Brevo Breach
Approximately 347,000 Trezor users were targeted in a phishing campaign following a breach of its third-party marketing platform, Brevo.
Breach Details
Trezor confirmed that a breach of its third-party marketing platform, Brevo, led to a phishing campaign targeting 347,000 customers. The incident involved unauthorized access to Brevo’s SAML Single Sign-On (SSO) configuration, allowing an attacker to compromise 138 accounts.
SSO Configuration Flaw
The attacker created a malicious Brevo account, enabled SSO, and invited legitimate users to join the compromised setup. By using their own identity provider, the threat actor accessed accounts and breached the intended scope of SSO functionality, gaining access to all organizations associated with the compromised users.
Phishing Campaign
The breach enabled the attacker to send phishing messages to email addresses stored in six affected accounts. Contact data from 43 accounts was also extracted. Trezor reported that phishing emails with the subject line “Critical Security Alert: STM32 Entropy Vulnerability” were distributed to 347,000 addresses linked to the compromised Brevo account.
Impact and Response
The malicious emails included a link to a phishing website, which was taken offline after 20 minutes. Trezor warned that users who clicked the link and entered wallet recovery information risked losing funds. Approximately 2,500 users interacted with the link, though the financial impact remains unspecified.
Additional Affected Organizations
Swiss Bitcoin hardware wallet provider BitBox and crypto tax platform CoinTracking also reportedly suffered breaches linked to the same incident. However, neither organization has provided details about the scope of the attack or directly attributed the breach to Brevo.
Previous Breach with ShipMonk
This incident follows a separate data exposure involving Trezor’s third-party shipping partner, ShipMonk. A September 4 update revealed that a breach of ShipMonk compromised personal information for 14,000 individuals, with an additional 67,000 U.S. customers affected. The exposed data included names, shipping addresses, phone numbers, and order details.
Implications and Recommendations
The breaches highlight vulnerabilities in third-party service integrations and the cascading effects of compromised SSO configurations. Organizations relying on shared infrastructure must prioritize rigorous access controls and continuous monitoring to mitigate similar threats.
According to Trezor, the phishing campaign underscores the importance of user vigilance and the need for robust security measures in third-party partnerships.
