Security Vulnerability in Brevo Login System Exposes 347K Trezor Users to Phishing Attack

Security Vulnerability in Brevo Login System Exposes 347K Trezor Users to Phishing Attack

An authorization flaw in Brevo's platform allowed unauthorized access to 138 customer accounts, resulting in phishing campaigns targeting users of Trezor, BitBox and CoinTracking services.

According to a postmortem analysis released by Brevo on Thursday, the breach resulted in phishing emails being dispatched from six different accounts, while contact information was extracted from 43 accounts, and an additional 93 accounts demonstrated no significant activity. The company did not clarify whether these categories had any overlap.

The malicious actor established a Brevo account, activated single sign-on functionality, and sent invitations to genuine Brevo users to join the configuration. According to Brevo, access permissions should have been restricted to that specific organization, however an authorization boundary malfunctioned and provided access to all organizations that the invited users had permissions to access.

This revelation builds upon the security alerts that were published by Trezor and BitBox on Wednesday, which identified their common service provider and clarified the reason why the malicious emails successfully passed standard authentication protocols and looked legitimate.

Cointelegraph contacted Brevo to request additional details but had not received a reply by the time of publication.

According to a blog post published by Trezor, the phishing communication, which carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability," included a hyperlink to an application that solicited users' wallet backups. The organization deactivated the domain at the DNS level in less than 20 minutes, however approximately 2,500 individuals had already accessed the link prior to the takedown.

Trezor spokesperson

BitBox stated that Brevo maintained only email addresses and language preference data. The company discovered no indication of compromised company credentials, downloaded contact lists, missing funds or exposed recovery phrases, but is operating under the assumption that the list was potentially accessed while it awaits Brevo's log files.

At the same time, CoinTracking reported that its Brevo account was used to send out an email with the subject line "Data Breach Notice: Please refresh API Keys as soon as possible." The company advised recipients to avoid clicking on any links contained within the email.