Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

Summary

Brevo, a marketing platform, was compromised by hackers who then used this access to send phishing emails to users of Trezor, BitBox, and CoinTracking. Approximately 347,000 Trezor users received these malicious emails.

IFF Assessment

FOE

The compromise of a marketing platform leading to phishing attacks against users represents a significant security incident that directly harms defenders.

Defender Context

This incident highlights the risks associated with third-party vendor compromises, particularly for companies handling sensitive user data. Defenders need to be vigilant about supply chain risks and potential downstream impacts from breaches impacting their service providers. Users should be educated on identifying and reporting phishing attempts.

Read Full Story →