Trezor phishing attack traced to Brevo login authorization flaw

3 hours ago 2



An authorization flaw in Brevo’s login system has allowed an attacker to access 138 customer accounts, leading to phishing emails sent through accounts used by Trezor, BitBox and CoinTracking. Summary A Brevo login flaw gave an attacker access to 138 customer accounts, including those used by Trezor, BitBox and CoinTracking. Phishing emails were sent through six accounts, while contact lists were exported from 43 accounts. A fraudulent Trezor email reached roughly 347,000 subscribers and sent around 2,500 people to a malicious link. Trezor is treating all 347,000 newsletter addresses as potentially known to the attacker and reusable for phishing. Brevo said in a Thursday postmortem that the attacker exploited a weakness involving its single sign-on system, gaining access to organizations connected to legitimate users who had been invited into an attacker-controlled Brevo account. The incident affected 138 customer accounts in total. Six were used to send phishing emails, contacts were exported from 43 accounts, while Brevo recorded no meaningful activity across another 93. The company did not specify whether those groups overlapped. Brevo flaw gave attacker access to customer organ...

Read Entire Article