Trezor, BitBox, and CoinTracking Subscribers Targeted by Phishing After Brevo SAML SSO Authorization-Boundary Breach
Trezor, BitBox, and CoinTracking Subscribers Targeted by (TL-2026-2445), also tracked as STM32 Entropy Vulnerability phishing campaign, is a high-severity phishing campaign, first published 2026-09-11. It has no confirmed attribution, affects Brevo Brevo Email Marketing / SAML SSO Platform (formerly Sendinblue), maps to 10 MITRE ATT&CK techniques (T1036.005, T1078.004, T1199), and is covered by 9 detection rules and 8 indicators of compromise.
Key facts for TL-2026-2445
- Threat ID
- TL-2026-2445
- Also known as
- STM32 Entropy Vulnerability phishing campaign, Brevo SSO breach
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-11
- Last reviewed
- 2026-09-11
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, finance, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
An attacker abused a SAML SSO authorization-boundary flaw in the Brevo (formerly Sendinblue) email-marketing platform to reach 138 client accounts, exfiltrate contact lists from 43, and use 6 to send brand-impersonating phishing emails to roughly 347,000 Trezor newsletter subscribers plus BitBox and CoinTracking customers. The Trezor lure, titled "Critical Security Alert: STM32 Entropy Vulnerability," drove about 2,500 clicks to a fake wallet-recovery-seed-harvesting tool before Trezor pulled the domain at DNS level within 20 minutes.
How Trezor, BitBox, and CoinTracking Subscribers Targeted by works
On 2026-09-09, Brevo — the third-party email/newsletter SaaS platform (formerly Sendinblue) used by hardware-wallet maker Trezor, Swiss hardware-wallet maker BitBox (Shift Crypto), and crypto tax tool CoinTracking — suffered a security incident rooted in its SAML single sign-on implementation. According to Brevo's postmortem, the attacker created their own Brevo account, enabled SSO, and invited legitimate Brevo customer-org users into that attacker-controlled SSO configuration. Access was intended to stay scoped to the attacker's own organization, but an authorization-boundary defect instead extended it to every organization the invited users could themselves reach. Brevo's investigation found 138 client accounts were touched, contact lists were exported from 43 of them, and 6 accounts were actually used to send phishing mail (93 accounts showed no meaningful attacker activity; Brevo did not clarify whether these categories overlap).
Using that access, the attacker sent phishing email from Trezor's legitimate Brevo-relayed sending identity (help@trezor.io), which meant the messages passed SPF/DKIM/DMARC checks. The Trezor lure — subject "Critical Security Alert: STM32 Entropy Vulnerability" — falsely claimed a hardware flaw in the STM32 microcontrollers used in Trezor devices could allow brute-forcing of wallet entropy/recovery seeds, and directed roughly 347,000 opt-in newsletter subscribers to a fake "Entropy Check" verification tool hosted on a newly registered look-alike domain designed to harvest 12/24-word wallet recovery seed phrases. Trezor detected the campaign and disabled the malicious domain at the DNS level within 20 minutes, but approximately 2,500 recipients had already clicked through. Trezor suspended its Brevo account, disabled the platform's email-sending function for its tenant, and posted public warnings across trezor.io, Trezor Suite, and support channels advising anyone who had entered a recovery seed to treat the funds as compromised and move them to a newly generated wallet immediately. Trezor stated it could not confirm whether the newsletter list itself had been exported, and that no other Trezor systems (beyond the newsletter database) were touched.
BitBox's compromised Brevo tenant held only email addresses and language preferences and was used to blast the full newsletter and tutorial distribution list with the same style of brand-impersonating alert; BitBox reported no evidence of compromised credentials or stolen funds. CoinTracking's subscribers received a differently worded lure, "Data Breach Notice: Please refresh API Keys as soon as possible," sent through the same compromised Brevo infrastructure. Brevo stated the unauthorized access was fully closed at 11:30 AM CEST on 2026-09-10. No malware family, C2 infrastructure, or specific phishing domain/IP has been publicly disclosed by Trezor, BitBox, CoinTracking, or Brevo as of publication; no CVE was assigned because the flaw is an application-level SaaS authorization-boundary/business-logic defect rather than a versioned software vulnerability, and the "STM32 entropy vulnerability" itself is fabricated — Trezor hardware has no disclosed entropy defect. Security commentary (Casa CEO Nick Neuman, cited in press coverage) tied the BitBox lure to the same shared Brevo compromise and framed the incident alongside other recent third-party-vendor breaches against hardware-wallet makers, including Trezor's own ShipMonk fulfillment-vendor breach (~80,689 customers' shipping data, disclosed within weeks of this incident) and a prior Ledger customer-data exposure tied to vendor Global-e — underscoring a pattern of attackers targeting the SaaS/vendor perimeter around hardware wallets rather than the devices themselves.
MITRE ATT&CK techniques used in TL-2026-2445
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1199 Trusted Relationship; T1566.002 Phishing: Spearphishing Link
Privilege Escalation
T1078.004 Valid Accounts: Cloud Accounts
Execution
T1204.001 User Execution: Malicious Link
Collection
T1213 Data from Information Repositories
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services
Impact
stealth
Affected products and versions in Trezor, BitBox, and CoinTracking Subscribers Targeted by
- Brevo — Brevo Email Marketing / SAML SSO Platform (formerly Sendinblue)
Vulnerable versions: Multi-tenant SaaS platform — all tenants prior to remediation
Fixed in: Authorization boundary remediated; unauthorized access confirmed fully closed 2026-09-10 11:30 CEST - Trezor (SatoshiLabs) — Trezor opt-in newsletter subscriber database (hosted on Brevo)
Vulnerable versions: ~347,000 subscriber records exposed to phishing send via compromised Brevo tenant
Fixed in: Brevo account suspended; email-sending function disabled - Shift Crypto — BitBox newsletter and tutorial distribution list (hosted on Brevo)
Vulnerable versions: Full newsletter/tutorial subscriber list exposed to phishing send
Fixed in: No credential or fund compromise reported - CoinTracking — CoinTracking customer/newsletter distribution list (hosted on Brevo)
Vulnerable versions: Subscriber list exposed to phishing send ('Data Breach Notice: Please refresh API Keys' lure)
Fixed in: Remediated alongside broader Brevo incident closure
Remediation for Trezor, BitBox, and CoinTracking Subscribers Targeted by
Patches
- Brevo remediated the SAML SSO authorization-boundary flaw; unauthorized access was confirmed fully closed at 11:30 AM CEST on 2026-09-10
Immediate actions
- Do not click links in unsolicited 'critical security alert' emails claiming to be from Trezor, BitBox, or CoinTracking; verify any claimed vulnerability directly through the vendor's official app, website, or support channel rather than an emailed link
- Anyone who entered a wallet recovery seed/backup phrase on the fake 'Entropy Check' tool must treat the associated funds as compromised and move them to a newly generated wallet immediately
- Brevo account access suspended, tenant email-sending function disabled, and the malicious domain taken down at the DNS level by Trezor within 20 minutes of detection
Workarounds
- Treat all inbound 'critical vulnerability' or 'security alert' emails referencing hardware wallets as unverified until confirmed out-of-band via the vendor's official app or support channel
- Never enter a hardware-wallet recovery seed into any website, browser extension, or downloaded application under any circumstance — legitimate wallet vendors never ask for it
Longer-term hardening
- Audit third-party SaaS/email-marketing vendors' SSO and multi-tenant authorization boundaries before granting them access to subscriber PII, and require vendor security attestations (e.g. SOC 2 Type II, penetration test results) as part of vendor onboarding
- Adopt multi-channel notification (in-app, official social accounts, support portal) for genuine critical security alerts so an email-only claim is inherently treated as unverified
- Enable BIP-39 passphrase protection on hardware wallets as a defense-in-depth layer that limits the blast radius of a phished recovery seed
Weaknesses (CWE) in Trezor, BitBox, and CoinTracking Subscribers Targeted by
CWE-863, CWE-284
Timeline of Trezor, BitBox, and CoinTracking Subscribers Targeted by
- Trezor publishes the public blog post 'Security incident at Brevo, our third-party email provider,' advising anyone who entered a recovery seed on the phishing site to move funds to a new wallet immediately.
- Trezor suspends its Brevo account and disables the platform's email-sending function for its tenant; warning messaging is added across trezor.io, Trezor Suite, and support channels.
- Trezor detects the phishing campaign and takes down the malicious 'Entropy Check' phishing domain at the DNS level within 20 minutes of discovery; approximately 2,500 recipients had already clicked through.
- Six compromised Brevo accounts are used to send brand-impersonating phishing email — including a Trezor-branded 'Critical Security Alert: STM32 Entropy Vulnerability' lure to roughly 347,000 opt-in newsletter subscribers, plus lures to BitBox's full newsletter/tutorial list and CoinTracking subscribers.
- Attacker creates a Brevo account, enables SAML SSO, and invites legitimate Brevo customer-org users into the attacker-controlled SSO configuration; an authorization-boundary defect extends the attacker's access to every organization the invited users could reach, ultimately touching 138 client accounts.
- Press reporting (Cointelegraph, TheCyberSecGuru, CryptoSlate) confirms BitBox and CoinTracking were also hit via the same compromised Brevo infrastructure, with CoinTracking subscribers receiving a distinct 'Data Breach Notice: Please refresh API Keys as soon as possible' lure.
- Brevo's postmortem discloses the full scope: 138 client accounts touched, contact lists exported from 43 accounts, 6 accounts used to send phishing mail, and 93 accounts showing no meaningful attacker activity (overlap between categories not clarified).
- Brevo confirms the unauthorized access is fully closed as of 11:30 AM CEST.
- SecurityWeek and other outlets publish broader coverage of the incident, framing it alongside Trezor's separate ShipMonk fulfillment-vendor breach (~80,689 customers) as part of a pattern of third-party-vendor compromises targeting hardware-wallet makers.
Sources cited for Trezor, BitBox, and CoinTracking Subscribers Targeted by
- Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
- Security incident at Brevo, our third-party email provider
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach
- Brevo Login Breach Affected Trezor, BitBox and CoinTracking
- Trezor, BitBox & CoinTracking Phishing Attack: Brevo Breach Explained
- Attackers exploit fake STM32 vulnerability alert to target Trezor and BitBox holders
- Trezor phishing shows attackers can skip the device and target the human trust layer
- Trezor Details Brevo Breach Behind Fake Security Alert
More in phishing
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration
- Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)
Detection coverage for TL-2026-2445
As of 2026-09-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2445 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.