Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

https://www.securityweek.com/wp-content/uploads/2026/04/bitcoin-cryptocurrency.jpeg

Cold cryptocurrency storage provider Trezor says roughly 347,000 of its customers received phishing emails after a third-party marketing platform used by the company was hacked.

The incident involved the marketing platform Brevo, which Trezor uses for newsletters. Brevo said an attacker exploited how it handles SAML Single Sign-On (SSO) to access 138 accounts.

“The attacker created a Brevo account and enabled single sign-on (SSO) on it, then invited legitimate Brevo users into that SSO configuration. Using their own identity provider, they were able to sign in as those invited users, which by itself is expected behavior for SSO,” Brevo explained.

“This access was not properly scoped: instead of being limited to the single organization where SSO was enabled, it wrongly granted the attacker access to all organizations those users could reach,” it added.

According to the company, the attacker sent phishing messages to the email addresses stored under six...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more

https://assets.bwbx.io/images/users/iqjWHBFdfxIU/idBOrNUlnLmA/v1/1200x809.jpg

Threat intelligence report: Anthropic says it disrupted a Yemen-based guided weapons engineering cell using Claude to develop guidance software for missiles

September 11, 2026, 9:15 AM Top News More: Axios, BBC, Financial Times, Quartz, The Record, Bloomberg, PCMag, Financial Times, Business Standard, Semafor, The Register, Tom's Hardware, Constellation Research, TechCrunch, MediaNama, Tech Times, Straight Arrow, Implicator.ai, The Rundown AI, CNBC, Cointelegraph, SecurityWeek, Cyber Security News, City A.