Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Trezor warns of phishing after Brevo breach hits customers

Trezor says a cyberattack on marketing tech company Brevo allowed hackers to send around 347,000 phishing emails to its customers. It is the second breach in as many months affecting a company Trezor relies on.

  • Trezor said a cyberattack on Brevo allowed hackers to send around 347,000 phishing emails to Trezor customers with a malicious link purporting to come from the wallet maker.
  • Brevo said hackers accessed 138 Brevo accounts and abused a flaw that meant their access was not properly scoped.
  • Trezor says none of its products, wallets or account system was affected.

Hardware crypto wallet maker Trezor is warning customers for the second time in as many months that one of the companies it relies on was hacked, exposing customer data to hackers.

In a blog post this week, Trezor said a cyberattack on Brevo, a marketing tech company it uses to send newsletters, allowed hackers to send around 347,000 phishing emails to Trezor customers with a malicious link purporting to come from the wallet maker. According to Trezor, one of the email subject lines said: "Critical Security Alert: STM32 Entropy Vulnerability."

The link, when tapped, downloads an app that asks the victim for their wallet backup password. With a stolen wallet password, a hacker can irreversibly steal the person's funds on the public blockchain.

Brevo said in an incident status post that the hackers were able to access 138 Brevo accounts to send out the mass volume of phishing messages. Brevo said the hackers abused a flaw that meant their access was "not properly scoped," and that their access was "wrongly granted" to all organizations the hackers' accounts could reach.

Trezor says none of its products, wallets or account system was affected by the incident. The company said it was reevaluating its relationships with its vendors and warned customers that their email addresses may be used again for future phishing attacks.

This is the second breach in recent weeks affecting Trezor, after the company alerted customers in August that one of its shipping partners was compromised. The incident at mailing company ShipMonk exposed the names, phone numbers, email addresses and postal addresses of at least 81,000 people who bought and received Trezor wallet hardware.

The data breach could put crypto owners and other wealthy individuals at risk of targeted violence and so-called "wrench" attacks, which rely on physical attacks to extract passwords from people. In the weeks following the ShipMonk breach, some people have received letters by mail claiming to be from Trezor, featuring a QR code that, when scanned, opens a fake page that attempts to steal the victim's crypto wallet password.

Why this matters: The breach highlights a common security incident where hackers compromise data held by third-party companies that are necessary for fulfilling orders or purchases from customers.

What this means for you: Trezor customers should be alert to emails claiming to come from the wallet maker, as their email addresses may be used again for future phishing attacks.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.