Trezor Warns of 347,000 Phishing Emails After Brevo Breach
Trezor says a Brevo hack let attackers send 347,000 phishing emails to customers, its second vendor breach in weeks.
In a blog post this week, Trezor said a cyberattack on Brevo, a marketing technology company it uses to send newsletters, allowed hackers to send the phishing emails to Trezor customers. The messages contained a malicious link that purported to come from the wallet maker; when tapped, the link downloaded an app that asked the victim for their wallet backup password. One subject line read, "Critical Security Alert: STM32 Entropy Vulnerability."
With a stolen wallet password, a hacker can irreversibly steal the person's funds on the public blockchain, Trezor said.
Brevo said in an incident status post that hackers accessed 138 Brevo accounts to send the mass volume of phishing messages. Brevo said the attackers abused a flaw that meant their access was "not properly scoped," and that access was "wrongly granted" to all organizations the hackers' accounts could reach.
Trezor said none of its products, wallets, or account system was affected by the incident. The breach highlights a common security incident in which hackers compromise data held by third-party companies that are necessary for fulfilling orders or purchases from customers.
This is the second breach in recent weeks affecting Trezor. In August, the company alerted customers that one of its shipping partners was compromised in a data breach. The incident at the mailing company ShipMonk exposed the names, phone numbers, email addresses, and postal addresses of at least 81,000 people who bought and received Trezor wallet hardware.
According to the report, the data breach could put crypto owners and other wealthy individuals at risk of targeted violence and so-called "wrench" attacks, which rely on physical attacks to extract passwords from people. In the weeks following the ShipMonk breach, some people received letters by mail claiming to be from Trezor, featuring a QR code that, when scanned, opened a fake page that attempted to steal the victim's crypto wallet password.
Trezor said it was reevaluating its relationships with its vendors and warned customers that their email addresses may be used again for future phishing attacks.