Crypto Newsletter Breach Triggers Fake Security Emails

The Record · Medium sophistication
Last updated September 10, 2026

Attackers abused access to a third-party email newsletter provider to send convincing “security alert” emails from legitimate-looking crypto company domains. The emails pushed users to click links that led to phishing sites designed to look nearly identical to real platforms. Trezor, CoinTracking, and BitBox warned customers not to click and said they are investigating and taking down malicious domains.

Key findings

  • Attackers breached a third-party email provider and used it to send phishing emails to crypto customers.
  • The phishing emails used legitimate company domains and pretended to be urgent security notices requiring customer action.
  • Victims reported clicking links that led to phishing websites “nearly identical” to legitimate platforms.
  • CoinTracking identified the impacted email service provider as Brevo; Brevo said an attacker accessed 120 customer accounts.
  • Trezor and BitBox warned customers not to click links and described efforts to take down phishing domains and investigate the incident.

Who’s being targeted

  • Commonly targeted roles: All staff (phishing awareness), Finance teams handling crypto payments, IT/Service Desk (handling user reports of suspicious emails), Security team / incident response, Developers and analysts who use API keys.
  • Affected industries: Cryptocurrency, Financial services, Technology/SaaS (email marketing/newsletter providers).
  • Attack channels: email, website.
  • Impersonated: Trezor (security team / security alert), CoinTracking (breach notification / account security).

Awareness takeaways

  • Treat urgent “security alert” emails as suspicious, verify using official channels before clicking any links.
  • A message can look legitimate (even from a real domain) and still be malicious if a third-party email provider is compromised.
  • Be cautious of breach notices telling you to rotate secrets (passwords/API keys) via an email link, go directly to the vendor site instead.
  • Report suspicious messages quickly so security teams can help take down phishing domains and warn others.

Red flags to watch for

  • Unexpected urgent security alert pushing immediate action via a link
  • Link leads to a site that only looks identical to the real platform
  • Message is sent via a third-party newsletter system rather than normal support channels
  • Pressure to take immediate action (“as soon as possible”) via an embedded link
  • Breach-themed message that routes to a lookalike website
  • Unexpected instruction to rotate sensitive credentials through an email link
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine getting this: “Critical Security Alert: STM32 Entropy Vulnerability” from Trezor. Looks legit, right? But in this breach, attackers abused Brevo’s newsletter system to send fake security emails for Trezor, CoinTracking, and BitBox, all pointing to phishing sites that look almost identical to the real platforms. Here’s the trap: the email uses real company domains, screams “refresh API keys as soon as possible,” and the link opens a site that feels perfect, logo, colors, everything, while quietly stealing your credentials. If an email says there’s a breach or wallet bug and tells you to click a link, don’t. Go to the site yourself or app you normally use, and check your account from there.

Similar attacks

Brevo Breach Sparks Trezor Phishing Wave

Brevo Breach Sparks Trezor Phishing Wave

Trezor said attackers breached its third-party email provider (Brevo) and gained access to Trezor’s email domain, triggering phishing emails to subscribers. The scam emails used a fake “critical security alert” about a supposed microcontroller vulnerability and attempted to trick users into handing…

September 10, 2026
Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
Fake M&A Wire Fraud and Trezor Phishing Alert

Fake M&A Wire Fraud and Trezor Phishing Alert

This bulletin describes multiple real-world scams where attackers manipulate trust to steal money or sensitive data. Notably, attackers impersonated executives to pressure legal teams into moving M&A discussions to WhatsApp/personal email to trigger international wire transfers, and Trezor users…

September 10, 2026
Spoofed Bank Domains Used for Account Takeovers

Spoofed Bank Domains Used for Account Takeovers

U.S. authorities extradited a Russian national accused of running a bank-account takeover scheme that used lookalike bank domains and paid search ads to trick victims into logging in to fake banking sites. The crew allegedly harvested thousands of banking credentials and then attempted large…

September 8, 2026
Phishers Hide “Funding” With Invisible Unicode

Phishers Hide “Funding” With Invisible Unicode

Microsoft reported a real, high-volume phishing campaign (up to millions of emails per day) that hid key “loan/funding” lure words using invisible Unicode characters to slip past email filters. The emails used disposable finance-themed domains and were often routed through ActiveCampaign…

September 4, 2026
Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026