Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Summary
Trezor has reported that a phishing campaign, stemming from a data breach at email marketing service Brevo, targeted approximately 347,000 of its users. Of those targeted, 2,500 users clicked a malicious link within the phishing emails.
IFF Assessment
This incident involves a data breach and subsequent phishing attacks, which are detrimental to users and defenders.
Defender Context
This incident highlights the cascading risk of third-party data breaches, where compromised data from one service (Brevo) is used to target customers of another (Trezor). Defenders should be aware of sophisticated phishing campaigns that leverage legitimate-looking email lists and advise users to be highly cautious of unsolicited communications, especially those containing links or requests for sensitive information.