Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor said phishing emails tied to a breach at Brevo targeted 347,000 email addresses and tricked 2,500 users into clicking a malicious link that tried to steal wallet backup information. The company also linked the campaign to earlier third-party breaches, including ShipMonk and a previous support portal intrusion, highlighting repeated exposure of customer data. #Trezor #Brevo #ShipMonk #ShinyHunters

Keypoints

  • Threat actors abused Brevo, Trezor’s third-party email provider, to send phishing emails.
  • The campaign targeted about 347,000 email addresses from Trezor’s newsletter list.
  • About 2,500 users clicked the malicious link before it was taken down.
  • The fake emails impersonated a critical security alert about an STM32 microcontroller flaw.
  • Trezor also recently faced breaches tied to its support portal and ShipMonk logistics provider.

Read More: https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/