Structured data rendered for: graph
Back to Blog

Brevo breach turns trusted crypto newsletters into phishing channels

Published
Updated
7 min read
Brevo breach turns trusted crypto newsletters into phishing channels

Brevo breach turns trusted crypto newsletters into phishing channels

Executive Summary

A compromise at Brevo, the email marketing provider used by several cryptocurrency companies, triggered a coordinated phishing campaign against newsletter subscribers of Trezor, BitBox, CoinTracking, and potentially other customers. Trezor said the incident affected roughly 347,000 opt-in newsletter email addresses, with 2,500 users clicking the malicious link before the domain was taken down at DNS level. Brevo later said 138 customer accounts were accessed, six were used to send phishing emails, and contacts were exported from 43 accounts.

The important lesson is not only that crypto users remain high-value targets. It is that attackers abused a legitimate communications provider and trusted brand domains to make urgent security warnings look believable. For security teams, this belongs in the same operational bucket as other third-party trust failures: marketing platforms, CRM systems, support portals, logistics providers, and transactional email tools can all become high-impact delivery channels when compromised.

What happened?

On September 9, 2026, Trezor warned customers that Brevo, its third-party newsletter platform, had suffered a security incident. An unauthorized actor used access to Brevo customer accounts to send malicious emails from legitimate customer communications channels.

For Trezor subscribers, the lure was a fake critical hardware-wallet security alert. The message claimed there was an STM32 entropy issue and pushed users toward a malicious link that asked them to download an app and enter their wallet backup. Trezor said no Trezor product, wallet system, or account platform was compromised, but it treated the newsletter list as exposed for future abuse.

The campaign was not limited to one brand. Recorded Future News reported that Trezor, BitBox, and CoinTracking confirmed phishing messages reached customers subscribed to their newsletters. BitBox said several cryptocurrency companies appeared to share the same newsletter provider, and CoinTracking named Brevo as the source of the compromised mail channel.

Brevo initially said 120 customer accounts were affected. Later reporting based on Brevo's postmortem put the number at 138 accessed accounts, with six used to send phishing emails and 43 having contacts exported. Brevo said the attacker was removed, the exploited issue was fixed, and the company planned to cooperate with authorities.

Why this incident matters

This incident shows how easily social engineering can cross from suspicious-looking inbox noise into something that feels legitimate. The messages came through real email infrastructure, used familiar brands, and focused on urgent security topics. That combination weakens the usual advice to "check the sender" because the sender path itself may be part of the compromised trust chain.

For crypto users, the stakes are unusually high. A recovery phrase is not just a password that can be reset. If a user enters a wallet backup into attacker-controlled software, funds can be moved away quickly and irreversibly. Trezor advised anyone who entered a wallet backup after following the link to move funds to a new wallet immediately.

For organizations, the incident is a reminder that marketing and customer engagement systems are part of the security perimeter. They hold audience lists, send authenticated messages at scale, and can create convincing calls to action under trusted domains. When those tools are compromised, the result can look like an official alert rather than a scam.

Category decision

This post is categorized as Supply Chain Attack. The immediate payload was phishing, and the victims were cryptocurrency users, but the core failure path was a trusted third-party email provider being abused to reach customers through legitimate business communications. The dominant defender action is to review vendor access, email platform controls, emergency communications processes, and customer warning workflows.

Impact and exposure

The known impact includes:

  • Trezor's roughly 347,000 newsletter email addresses treated as potentially reusable for future phishing.
  • 2,500 Trezor users who clicked the malicious link before DNS takedown limited further access.
  • Brevo's 138 accessed customer accounts, according to reporting based on its postmortem.
  • Six Brevo customer accounts used to send phishing emails.
  • Contacts exported from 43 Brevo accounts, creating possible future targeting risk.

Trezor said Brevo did not hold wallet data, passwords, or funds. That distinction matters, but it does not make the event harmless. A list of verified crypto users is valuable for follow-on targeting, especially when combined with urgency, brand impersonation, and prior exposure from unrelated vendor incidents.

What defenders should do now

1. Treat email platforms as privileged systems

Marketing and CRM platforms should be governed like systems that can cause customer-facing incidents. Enforce MFA, SSO, conditional access, admin role minimization, and logging for all accounts with send permissions. If the platform supports approval workflows for large sends or security-themed templates, use them.

2. Audit vendor access and integrations

Review who can access mailing lists, export contacts, change templates, modify tracking domains, or trigger campaigns. Disable stale users, reduce API token scope, and rotate credentials connected to newsletter or CRM workflows.

3. Prepare customer warning channels before a crisis

Organizations should have a predefined path for emergency customer warnings outside the compromised channel. That may include in-app banners, website notices, status pages, signed security advisories, support macros, and social media confirmations. Incident communications should not depend on the same system that may be under attacker control.

4. Monitor for suspicious campaign activity

Security teams should alert on unusual exports, sudden large sends, template edits containing security warnings, new redirect domains, and campaign launches outside normal business hours. Logs from marketing systems belong in security monitoring, not only in growth or CRM analytics.

5. Plan for follow-on targeting

If contact lists were exported, the incident response does not end when the first phishing domain is taken down. Expect later waves using similar lures, new domains, SMS, social platforms, or even postal targeting where attackers can combine multiple exposed datasets.

Guidance for affected users

Users who received one of these messages should avoid clicking links from the email and should verify any urgent wallet warning through the vendor's official website or application. Anyone who entered a wallet backup, seed phrase, recovery phrase, API key, or login secret after following the link should treat the secret as compromised.

In Trezor's case, the company said clicking the link alone does not expose funds if the wallet backup was not entered. The high-risk action is entering the recovery material into an app or website. Hardware wallet users should remember the simple rule: the recovery phrase belongs only on the physical device during recovery, never in a browser, app download, form, support chat, or email flow.

Detection and investigation pointers

Organizations using third-party mailing platforms should look for:

  • new or unusual admin logins, especially from unfamiliar geographies or devices
  • contact export events, particularly for high-value customer segments
  • security-themed email templates created or modified outside normal process
  • new redirect domains, tracking links, or shortened URLs in campaigns
  • campaigns launched from dormant accounts or unusual sender profiles
  • support tickets reporting urgent security emails that internal teams did not approve
  • downstream account takeover attempts against customers who received campaign emails

Teams should also compare email authentication results with campaign logs. Passing SPF, DKIM, or DMARC does not prove the message was safe if the attacker used authorized infrastructure.

Strategic takeaway

Trusted communications systems are becoming an attractive compromise path because they give attackers reach, legitimacy, and urgency in one move. The Brevo incident turned ordinary newsletter infrastructure into a targeted phishing channel for crypto users, but the same pattern applies to SaaS vendors, banks, healthcare platforms, and enterprise software providers.

The defensive shift is straightforward: customer messaging platforms need security ownership, not just marketing ownership. If a system can send trusted instructions to thousands of users, export customer contacts, or route links through official domains, it deserves the same level of access control, monitoring, and crisis planning as other high-impact business systems.

References

  1. Security incident at Brevo, our third-party email provider
  2. Multiple crypto companies warn customers of phishing emails after alleged provider breach
  3. Crypto customers targeted by scammers after email marketing provider breach

FAQ

How to cite

Lucas Oliveira. Brevo breach turns trusted crypto newsletters into phishing channels. 13 Sept 2026. Invaders Cybersecurity. https://invaders.ie/resources/blog/supply-chain-attack/brevo-crypto-newsletter-phishing-supply-chain.

Subscribe via RSS.

Written by

Lucas Oliveira

Research

A DevOps engineer and cybersecurity enthusiast with a passion for uncovering the latest in zero-day exploits, automation, and emerging tech. I write to share real-world insights from the trenches of IT and security, aiming to make complex topics more accessible and actionable. Whether I’m building tools, tracking threat actors, or experimenting with AI workflows, I’m always exploring new ways to stay one step ahead in today’s fast-moving digital landscape.