Analysis-Houthi advance in Yemen puts U.S. in a new bind
Yemeni Government Forces Strike Houthi Vessels in Taiz Region
Xi Sits Down With Modi on First Trip to India in Seven Years
Iraq and Iran to Jointly Investigate Drone Launchers on Border
RBI Rejects Tata Sons Plea to Nix Shadow Lender Tag, Reports Say
Bahrain Declines Participation in Iran Meeting Regarding Hormuz Strait
HDFC Bank Submits Names of Two CEO Candidates to RBI
Oil Supply Risks Rise After Saudi Pipeline Attack
Modi Seeks BRICS Unity as Global Tensions Rise
BRICS 2026: Modi Seeks Bigger Role For Global South
BRICS Countries Call for Maximum Restraint in the Middle East
Trump Signals US Wants Distance From Iran War
Iranian President Urges BRICS to Oppose Targeting of Civilian Infrastructure
Dell Technologies (DELL) Stock Reaches Record Peak as Founder Climbs to Third Wealthiest Globally
Markets Defy Logic: Stocks Surge 1% Despite Scorching Inflation Numbers
Rocket Lab (RKLB) Stock Gains Analyst Support Despite 46% Decline
GE Vernova (GEV) Stock: Is the Recent 23% Decline Creating a Strategic Entry Point?
Iraq Fires Maysan Commander After Drone Attacks on Saudi Arabia’s Pipeline
Tesla (TSLA) Semi Truck Expansion: European Launch Confirmed for 2027
Cathie Wood’s ARK Invest Pivots to Meta (META) and Rocket Lab in September Trading Activity
Nvidia (NVDA) Eyes $10B Stake in Anthropic’s Historic $2 Trillion IPO
General Motors to Develop Domestic Battery Supply Chains Amid Political Tensions
Iraqi Parliament Speaker Emphasizes State Control Over Weapons
Can Venezuela Rescue the Oil Market?
Can China’s Icicle woo global shoppers in a luxury downturn?
After the I.P.O., a Billion-Dollar Bill for Employee Paydays
Trump Criticizes Europe on Immigration, Trade, and NATO Cooperation
Iraqi Parliament Speaker Backs Urgent Investigation into Recent Attacks
Mexican Authorities Investigate Suspected Cartel-Linked Crypto Mining Operation
Iraqi Prime Minister Dismisses Police Chief in Maysan Province
Iran President and Abu Dhabi Crown Prince Hold Meeting in New Delhi
Iranian President Calls on BRICS to Address Unilateral Sanctions
HDFC Bank Submits Names of Two Candidates for CEO Role to RBI
China's Xi Urges Peace at BRICS Summit Amid Middle East Tensions
Donald Trump Voices Support for Irish Unification
U.S.-Canada trade war set to hit hard in midterm battleground states
Why a $5,000 Trump dividend check won’t solve your money woes
Nvidia (NVDA) Stock Analysis: CEO Jensen Huang Reaffirms $4 Trillion AI Market Vision
Xi Jinping Urges BRICS Nations to Uphold Historical Justice at Summit
Citi sees Fed delivering "a dovish hike" next week
Revolut Data Breach: Fraudulent Government Email Leads to Bitcoin Record Leak
Robinhood (HOOD) Crypto Trading Surges 61% Monthly But Lags 38% Behind 2025 Figures
Oil and Gas Markets Signal Winter Crisis and Rising Interest Rates
Hyperliquid (HYPE) Surges Past $82: Whale Accumulates $322M as Token Burn Accelerates
Former Anthropic Employees Resign Over AI Safety Failures, Warn of Existential Risks
War In the Middle East Crisis is Making Clothes More Expensive
Leaders Arrive At Bharat Mandapam
Trump Affirms Friendship with Saudi Crown Prince Amid Pipeline Attack Concerns
Bitcoin (BTC) Rallies Past $79K as CPI Data Shows Mixed Inflation Signals
What Many Miss Regarding the US-China Rivalry: New Economy
BRICS agrees to joint declaration in test of unity despite Mideast tensions
Trump says Iran war likely to end after midterms as Yemen fighting escalates
Maharashtra Pilots Asset Tokenization as India Embraces Blockchain for Power Grids and Bonds
Trump says Iran probably responsible for attack on Saudi pipeline
Trump Suggests Iran Likely Behind Saudi Pipeline Attack
Iran Signals Potential Shift in Nuclear Policy
Ethereum (ETH) Breaks Past $2,600 Despite Rate Hike Concerns, Reaches Multi-Month Peak
Ford Issues Recall for U.S. Vehicles Over Fuel Tank Hazard
Christine Lagarde: Europe seen from Normandy
Canadian boycott of US products pushes grocers to adapt, explore new supply sources
Iran Shifts to Offensive Military Strategy, Lawmaker States
BRICS 2026: Leaders Arrive At Bharat Mandapam
Canada seeks $1tn from investors looking for a haven from Donald Trump
News Quiz for September 12, 2026
Huawei Technologies Develops Large Language Model for Tourism Content
BRICS Members Reach Joint Declaration Condemning Unilateral War
Iran President Confirms Supreme Leader Mojtaba Khamenei is Alive
Chart of the Week: the long shadow of quantitative easing
Wall Street Economists Adjust Core PCE Forecasts Following CPI Data
Brevo Security Breach Exposes 347,000 Trezor Users to Phishing Attack
Key Takeaways
- An authentication vulnerability in Brevo’s email service enabled unauthorized access to 138 customer accounts
- Approximately 347,000 Trezor newsletter recipients were sent a phishing message with a fraudulent link
- Hardware wallet providers BitBox and tax platform CoinTracking also experienced unauthorized access via their Brevo accounts
- Roughly 2,500 individuals clicked the malicious link before Trezor shut down the fraudulent domain in under 20 minutes
- According to Trezor, no user credentials, wallet information, or core product infrastructure was compromised
An authentication weakness in Brevo, a widely-used email marketing service, enabled an unauthorized party to compromise 138 customer accounts and distribute phishing messages to hundreds of thousands of cryptocurrency holders.
The security incident impacted Trezor, BitBox, and CoinTracking—three prominent cryptocurrency companies that rely on Brevo for managing their subscriber communications.
Details of the Security Exploit
The threat actor established a Brevo account, activated single sign-on functionality, and sent invitations to genuine Brevo account holders to join their workspace. A critical authorization boundary defect subsequently provided the attacker with access to all organizations associated with those invited accounts.
Brevo’s subsequent investigation revealed that six compromised accounts were utilized to distribute phishing messages, 43 accounts had subscriber data extracted, and 93 accounts displayed no significant unauthorized activity.
The campaign was carefully designed to circumvent standard email verification protocols, causing the fraudulent messages to appear legitimate to unsuspecting recipients.
The Phishing Campaign Targeting Trezor Users
All 347,000 individuals subscribed to Trezor’s newsletter received a fraudulent message with the headline “Critical Security Alert: STM32 Entropy Vulnerability.”
The message directed recipients to a counterfeit application designed to capture wallet recovery phrases, which would grant attackers complete control over victims’ cryptocurrency holdings.
Trezor’s security team deactivated the malicious domain through DNS-level intervention within 20 minutes of identifying the threat. However, approximately 2,500 users had already accessed the fraudulent link prior to its removal.
Trezor emphasized that its Brevo account contained exclusively opt-in newsletter email addresses. No authentication credentials, private keys, or additional personal details were stored on the platform.
The hardware wallet manufacturer is now considering all 347,000 affected email addresses as potentially exposed and vulnerable to subsequent phishing operations.
Impact on BitBox and CoinTracking
BitBox reported that the malicious email successfully reached subscribers on both its newsletter and educational tutorial distribution lists via Brevo. The company’s investigation found no indication of contact database downloads, stolen funds, or compromised seed phrases.
BitBox verified that its Brevo database contained solely email addresses and user language preference settings.
CoinTracking’s compromised Brevo account was exploited to distribute a message with the subject line “Data Breach Notice: Please refresh API Keys as soon as possible.” The platform immediately instructed users to disregard and avoid interacting with any links contained in that communication.
Trezor has since terminated its Brevo service agreement and implemented prominent security warnings throughout its website, mobile application, and customer support platforms.
If you submitted your recovery phrase after accessing the malicious link, Trezor strongly recommends transferring all assets to a newly generated wallet without delay. Simply clicking the link without providing sensitive information does not compromise your funds.
Trezor has announced it is conducting a comprehensive audit of its third-party service providers and strengthening security protocols across all vendor relationships.
Source: Parameter
SECURITY WARNING
Click any links
(@coinjoined)