๐Ÿ“… Friday, 11 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Celah SSO Brevo Jebol 138 Akun Klien - Namun Target Utamanya Justru 347 Ribu Pengguna Trezor

Brevo SSO Flaw Breaches 138 Client Accounts - 347K Trezor Users Targeted

A postmortem report from email service provider Brevo revealed that attackers exploited a Single Sign-On (SSO) authorization flaw in its systems. The vulnerability allowed hackers to gain unauthorized access to 138 client accounts, leading to the distribution of phishing emails across crypto user bases.

The exploit affected 347,000 newsletter email addresses belonging to Trezor customers. All of those addresses were targeted in a mass phishing campaign disguised as an official security advisory under the fake subject line “Critical Security Alert: STM32 Entropy Vulnerability.”

Beyond Trezor, two other crypto industry entities reported similar incidents. Hardware wallet manufacturer BitBox and portfolio tracking platform CoinTracking confirmed their Brevo accounts were used by hackers to distribute fraudulent emails to their users.

Exploiting System Weaknesses

Brevo detailed the attack chain, which began when the threat actor created a new Brevo account and enabled SSO configuration. The attacker then invited legitimate user accounts into the system.

An authorization boundary failure at this stage granted the attacker access to all organizations linked to the victim’s account. Brevo broke down the scope of exploitation across the 138 compromised accounts into three activity tiers:

  • Six accounts: Actively used to blast phishing emails to user bases.
  • Forty-three accounts: Suffered data theft after the attacker exported contact lists.
  • Ninety-three accounts: Show no signs of further malicious activity.

A 20-Minute Attack Window

Trezor stated that the malicious domain operated by the attacker was taken down at the DNS level within 20 minutes of detection. Despite the narrow window, the company noted that approximately 2,500 users clicked the fraudulent link before access was fully blocked.

The domain takedown disrupted the initial attack vector directly targeting Trezor users. However, findings showing that attackers obtained exported contact lists from 43 separate accounts raise the risk of secondary phishing attempts against victims across other communication channels. Reported via Cointelegraph.

Previously: Hackers Breach Trezor Email and Send Fake STM32 Alert - Passed Official Verification


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share