Cointelegraph iconCointelegraphSep 11, 2026 ~1 min source read

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

The platform did not specify whether the categories overlapped. The attacker created a Brevo account, enabled single sign-on and invited legitimate Brevo users into the configuration.

Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

Share this story

Send the public story page.

Useful takeaways from this story.

The attacker created a Brevo account, enabled single sign-on and invited legitimate Brevo users into the configuration.

Brevo said access should have been confined to that organization, but an authorization boundary failed and granted access to every organization the invited users could reach.

The platform did not specify whether the categories overlapped.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

The attacker created a Brevo account, enabled single sign-on and invited legitimate Brevo users into the configuration. Brevo said access should have been confined to that organization, but an authorization boundary failed and granted access to every organization the invited users could reach. The platform did not specify whether the categories overlapped.

Details worth keeping

The platform did not specify whether the categories overlapped.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app