What happened
About 2,500 Trezor users clicked a malicious link that was sent in a phishing email, and the site was taken down only 20 minutes after it was spotted.
How the Brevo SSO flaw was abused
Brevo confirmed that an attacker leveraged a weakness in its SAML Single Sign‑On implementation. By creating a fresh Brevo account, turning on SSO and then inviting legitimate Brevo users into that configuration, the attacker could sign in as those users.
The compromised SSO token was not limited to the invited accounts; it gave the attacker read access to every organization reachable through the invited users. In practice the attacker harvested contacts from 43 Brevo accounts and used six of those accounts to dispatch phishing messages.
Phishing campaign details
The emails carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and a link to a malicious website that asked victims to paste their wallet backup. Trezor warned that anyone who entered that information could lose funds.
Roughly 347,000 Trezor customers received the email; about 2,500 clicked the link before the page was shut down.
Who else might be in the cross‑fire
BitBox and CoinTracking have been mentioned in media reports as possibly impacted, but neither company has confirmed any breach or linked the incident to Brevo.
Unconfirmed: BitBox and CoinTracking have not verified any compromise.
Past Brevo‑related incidents at Trezor
Trezor previously disclosed a breach of its third‑party shipping provider ShipMonk, which exposed personal data of nearly 14,000 people, later updated to include an additional 67,000 U.S. customers.
What organizations can do now
- Assume that any email from an unknown sender that references a “critical security alert” is suspicious.
- Check SAML SSO configurations for overly broad scopes; enforce least‑privilege token policies.
- Invalidate all active Brevo API keys and reset passwords for any accounts that used Brevo for communications.
- Monitor blockchain wallets for unexpected withdrawals and educate users to never share backup phrases.
- Implement multi‑factor authentication on all privileged accounts, especially those that can invite users into SSO setups.
