In a significant cybersecurity incident, Trezor, a leading provider of cold storage for cryptocurrencies, reported that approximately 347,000 of its users received phishing emails. This follows a breach of Brevo, a third-party marketing service used by Trezor.
Details of the Brevo Security Breach
The security breach involved the marketing platform Brevo, which Trezor utilizes for distributing newsletters. Brevo disclosed that an attacker exploited their SAML Single Sign-On (SSO) configuration, which allowed unauthorized access to 138 accounts. The attacker created a Brevo account, enabled SSO, and then invited legitimate users into this configuration, gaining access as those users through their own identity provider.
Brevo admitted that the access was not properly restricted, inadvertently allowing the attacker to reach all organizations the users could access, rather than just the intended single organization. This oversight enabled the attacker to send phishing emails using compromised accounts.
Impact on Trezor and Its Customers
The breach led to phishing messages being sent to email addresses associated with six compromised accounts. Trezor was among the affected, with the attacker sending phishing emails to 347,000 email addresses stored in Brevo’s system. The emails bore the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and directed recipients to a malicious website.
Trezor cautioned users against interacting with the site, warning that funds could be lost if wallet information was entered. Despite the threat, Trezor confirmed that only 2,500 users clicked on the link before the malicious site was shut down, 20 minutes after the breach was detected. The extent of potential financial loss remains unclear.
Broader Implications and Previous Incidents
The Brevo breach also impacted other cryptocurrency services, including BitBox and CoinTracking, although they have yet to disclose details. This incident comes shortly after another breach involving Trezor, where a third-party shipping provider, ShipMonk, exposed the personal information of nearly 14,000 users. An update revealed an additional 67,000 US customers were affected, with compromised data including names, emails, and shipping details.
These incidents highlight ongoing risks for Trezor users, as phishing attempts may increase in the wake of these breaches. Users are urged to remain vigilant and monitor communications for suspicious activity.
As the cryptocurrency industry continues to grow, ensuring robust cybersecurity measures is crucial to protect sensitive user data and maintain trust in digital asset management services.
