Brevo Login Flaw Sends Phishing Emails to 347,000 Trezor Newsletter Subscribers
TLDR
- A flaw in email platform Brevoโs login system gave an attacker access to 138 client accounts
- Around 347,000 Trezor newsletter subscribers received a phishing email containing a malicious link
- BitBox and CoinTracking were also affected through their Brevo accounts
- About 2,500 people clicked the link before Trezor took down the domain within 20 minutes
- Trezor says no wallet data, passwords, or product systems were compromised
A security flaw in email marketing platform Brevo allowed an attacker to access 138 client accounts and send phishing emails to hundreds of thousands of crypto users.
๐จ SECURITY WARNING ๐จ
Brevo (formerly Sendinblue) has reportedly been compromised. Phishing emails impersonating CoinTracking, Trezor and BitBox and likely several others in the industry are currently making the rounds.
DO NOT:
โ Click any links
โ Download attachments
โโฆ pic.twitter.com/yW30XrNV1R- Coinjoined Chris โก (@coinjoined) September 9, 2026
The breach affected Trezor, BitBox, and CoinTracking, all of which used Brevo to manage their newsletter lists.
โฆ Continue reading the full article at the original source below.

