Loading...
The Brevo vulnerability on the email platform allowed attackers to access 138 customer accounts and send phishing emails to 347000 Trezor subscribers. BitBox and CoinTracking accounts were also affected. Trezor disabled related domain names within 20 minutes, and approximately 2500 people visited phishing links. Brevo claimed that attackers exploited a single sign on vulnerability, in which 6 accounts were used to send emails, contact data for 43 accounts was exported, and BitBox and CoinTracking did not detect any fund or recovery phrase leaks. (Source: Cointelegraph)