• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

Trezor Says 347,000 Customers Obtained Phishing Emails After Brevo Hack

Admin by Admin
September 11, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Chilly cryptocurrency storage supplier Trezor says roughly 347,000 of its clients acquired phishing emails after a third-party advertising and marketing platform utilized by the corporate was hacked.

The incident concerned the advertising and marketing platform Brevo, which Trezor makes use of for newsletters. Brevo mentioned an attacker exploited the way it handles SAML Single Signal-On (SSO) to entry 138 accounts.

“The attacker created a Brevo account and enabled single sign-on (SSO) on it, then invited respectable Brevo customers into that SSO configuration. Utilizing their very own id supplier, they had been in a position to register as these invited customers, which by itself is anticipated habits for SSO,” Brevo defined.

“This entry was not correctly scoped: as a substitute of being restricted to the one group the place SSO was enabled, it wrongly granted the attacker entry to all organizations these customers may attain,” it added.

In line with the corporate, the attacker despatched phishing messages to the e-mail addresses saved underneath six of the compromised accounts. As well as, the menace actor exfiltrated contacts from 43 accounts.

One of many clients whose e mail record was abused for a phishing marketing campaign seems to be Trezor, which knowledgeable clients on Thursday that the attacker despatched phishing messages to 347,000 e mail addresses saved within the Brevo account.

Commercial. Scroll to proceed studying.

The phishing emails had the topic line “Crucial Safety Alert: STM32 Entropy Vulnerability” and contained a hyperlink pointing to a malicious web site. 

Trezor has not shared particulars in regards to the malicious web site, however warned clients that their funds might be misplaced in the event that they clicked on the hyperlink and entered their pockets backup.

In line with Trezor, solely 2,500 customers clicked on the hyperlink earlier than the malicious web site was taken offline 20 minutes after the incident was detected. It’s unclear what number of customers could have misplaced funds and the way a lot.

Swiss Bitcoin {hardware} pockets maker BitBox and crypto tax calculator CoinTracking additionally seem to have been hit by the Brevo hack, however they haven’t shared particulars on the impression and haven’t named Brevo because the supply of the incident.

The incident comes lower than a month after Trezor admitted that the non-public info of almost 14,000 folks was compromised in a knowledge breach affecting its third-party transport supplier ShipMonk.

An replace Trezor shared on September 4 revealed that the ShipMonk leak impacts a further 67,000 US clients, together with their identify, e mail, transport tackle, cellphone quantity, and order quantity.

Each incidents may result in a surge in phishing assaults focusing on Trezor clients.

Associated: Surfshark Techniques Focused by Hackers

Associated: 4.1 Million Impacted by AdaptHealth Knowledge Breach

Associated: Mathspace Knowledge Breach Exposes Over 1 Million Folks

Tags: BrevoemailsHackPhishingReceivedTrezorusers
Admin

Admin

Next Post
Cohere Releases North Small Translate: A 218B MoE Translation Mannequin That Scores 83.6 on WMT26 Throughout 50 Languages

Cohere Releases North Small Translate: A 218B MoE Translation Mannequin That Scores 83.6 on WMT26 Throughout 50 Languages

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

What Is Speaker Diarization? A 2025 Technical Information: High 9 Speaker Diarization Libraries and APIs in 2025

What Is Speaker Diarization? A 2025 Technical Information: High 9 Speaker Diarization Libraries and APIs in 2025

August 22, 2025
Chainguard Banks $280M for International Open-Supply Safety Play

Chainguard Banks $280M for International Open-Supply Safety Play

November 2, 2025

Trending.

AI & data-driven Starbucks – Deep Brew

AI & data-driven Starbucks – Deep Brew

May 18, 2026
High LLM Observability and Analysis Platforms in 2026: Langfuse, LangSmith, Braintrust, Arize, and Extra In contrast

High LLM Observability and Analysis Platforms in 2026: Langfuse, LangSmith, Braintrust, Arize, and Extra In contrast

August 9, 2026
Self-Coding AI: Breakthrough or Hazard?

Self-Coding AI: Breakthrough or Hazard?

July 4, 2025
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
Hasbro Information Breach Uncovered Worker Private Data

Hasbro Information Breach Uncovered Worker Private Data

August 30, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Pastime mindset | Seth’s Weblog

Solace | Seth’s Weblog

September 11, 2026
ClickFix assaults infecting PCs and Macs are going viral

ClickFix assaults infecting PCs and Macs are going viral

September 11, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved