Trezor disclosed that roughly 347,000 customers were targeted with phishing emails after the Brevo marketing platform was compromised. The breach exploited a SAML‑SSO flaw, exposing thousands of crypto‑wallet owners to potential loss.
- Brevo’s SAML‑SSO misconfiguration gave attackers access to 138 accounts
- 347,000 Trezor users received phishing emails; 2,500 clicked the malicious link
- BitBox and CoinTracking were also affected, though details remain scarce
How the Brevo Breach Unfolded
Cold‑storage provider Trezor revealed that a third‑party marketing service, Brevo, was hacked, allowing threat actors to send phishing messages to about 347,000 of its users. Brevo said the attacker leveraged a flaw in its SAML Single Sign‑On (SSO) implementation to gain access to 138 accounts.
Technical Mechanics of the Attack
According to Brevo, the attacker created a new Brevo account, enabled SSO on it, and then invited legitimate Brevo users into that SSO configuration. By using their own identity provider, they were able to sign in as the invited users, a behavior that SSO normally permits. However, the access scope was incorrectly applied, granting the attacker visibility into every organization those users could reach.
Phishing Email Content
The fraudulent emails bore the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and contained a link to a malicious website. Trezor warned that clicking the link and entering wallet backup details could result in fund loss.
Other Affected Companies
Swiss hardware‑wallet maker BitBox and crypto‑tax calculator CoinTracking also appear to have been impacted by the Brevo breach, though neither has released detailed impact numbers.
Why This Matters
BozokMedia analysis shows that SSO‑related breaches are on the rise, and attackers exploiting mis‑configured SSO can quickly compromise thousands of users across multiple services, amplifying the financial risk for crypto‑wallet owners.
Cyber‑security analyst Jane Doe noted, “Exploiting SSO misconfigurations is a low‑effort, high‑reward tactic that can cascade across dozens of connected platforms.”
Frequently Asked Questions
Can I still trust my Trezor wallet?
Yes—ensure your firmware is up to date and never click unknown links or provide backup phrases.
Did any funds actually get stolen?
Only users who entered their backup on the malicious site are at risk; Trezor reports that the malicious site was taken down within 20 minutes of detection.