Overview
- Brevo confirmed an authorization/SSO boundary flaw that gave an attacker access to 138 customer accounts, with six accounts used to send phishing emails and contacts exported from 43 accounts.
- Trezor says about 347,000 newsletter addresses were targeted, the malicious domain was disabled at the DNS level within 20 minutes, and roughly 2,500 recipients clicked the fraudulent link before it went offline.
- The phishing message used the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and directed victims to a fake app designed to request wallet recovery phrases that would allow attackers to drain funds if submitted.
- This campaign builds on an earlier ShipMonk compromise tied to a Metabase SQL‑injection zero‑day that left roughly 81,000 customer order records exposed, creating high‑fidelity contact data that can be reused in follow‑on scams.
- Companies have suspended affected Brevo accounts, warned customers not to enter recovery phrases, and are reviewing vendor controls and data‑retention practices while regulators and legal scrutiny are likely next steps.