logo

Crypto customers targeted by scammers after email marketing provider breach

ID: ab24b0d6-4506-5734-9c7c-708285f39fa7

STIX ID: report--ab24b0d6-4506-5734-9c7c-708285f39fa7

Feed Name: Malwarebytes Blog

Threat Score
75/100

Date Published: 2026-09-11

Date Updated: 2026-09-12

...
...

An attacker exploited a SAML SSO handling flaw in Brevo to access 138 customer accounts; six accounts were used to send phishing emails and 43 had contact lists exported. The phishing targeted cryptocurrency newsletter subscribers (notably Trezor’s ~347,000 subscribers) with convincing emails containing malicious links that asked recipients to download apps and enter wallet backups, creating a material risk of crypto theft and future targeted attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.