According to Huoxing Finance, on September 11, the email marketing platform Brevo disclosed that attackers exploited a privilege escalation vulnerability in its login system to access 138 customer accounts. Of these, six accounts were used to send phishing emails, 43 accounts had their contact information exfiltrated, and 93 accounts showed no active usage. Brevo did not clarify whether these categories overlapped. Affected customers included cryptocurrency hardware wallet manufacturers Trezor and BitBox, as well as the crypto portfolio and tax reporting platform CoinTracking. Using Trezor’s Brevo account, the attackers sent phishing emails titled “Critical Security Alert: STM32 Entropy Vulnerability” to approximately 347,000 newsletter subscribers, tricking users into accessing a fraudulent application and submitting their wallet backup information. Trezor blocked the associated domains at the DNS level within 20 minutes, but by then, around 2,500 users had already clicked the links. Trezor stated that its Brevo account stored only the email addresses of newsletter subscribers and no other customer data; however, it is treating all approximately 347,000 email addresses as compromised and potentially usable for future phishing attempts. BitBox has found no evidence of fund or mnemonic theft; CoinTracking users received fraudulent emails requesting them to refresh their API keys.
Brevo security breach affects 138 accounts; 347,000 Trezor users targeted with phishing emails
MarsBitShare
On September 11, the email platform Brevo disclosed a security vulnerability that allowed attackers to access 138 accounts, six of which were used to send phishing emails. Trezor, BitBox, and CoinTracking were affected, with 347,000 Trezor users targeted by a phishing email concerning an STM32 vulnerability. Trezor swiftly blocked the malicious domain, but 2,500 users still clicked the link. The incident may influence the Fear & Greed Index as traders reassess risk levels. Altcoins under scrutiny could experience increased volatility amid rising security concerns. Trezor confirmed that only email addresses were stored, but all are now considered compromised.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.



