Cold cryptocurrency storage provider Trezor says roughly 347,000 of its customers received phishing emails after a third-party marketing platform used by the company was hacked.
The incident involved the marketing platform Brevo, which Trezor uses for newsletters. Brevo said an attacker exploited how it handles SAML Single Sign-On (SSO) to access 138 accounts.
“The attacker created a Brevo account and enabled single sign-on (SSO) on it, then invited legitimate Brevo users into that SSO configuration. Using their own identity provider, they were able to sign in as those invited users, which by itself is expected behavior for SSO,” Brevo explained.
“This access was not properly scoped: instead of being limited to the single organization where SSO was enabled, it wrongly granted the attacker access to all organizations those users could reach,” it added.
According to the company, the attacker sent phishing messages to the email addresses stored under six of the compromised accounts. In addition, the threat actor exfiltrated contacts from 43 accounts.










