Attackers abused access to a third-party email newsletter provider to send convincing “security alert” emails from legitimate-looking crypto company domains. The emails pushed users to click links that led to phishing sites designed to look nearly identical to real platforms. Trezor, CoinTracking, and BitBox warned customers not to click and said they are investigating and taking down malicious domains.
Key findings
- Attackers breached a third-party email provider and used it to send phishing emails to crypto customers.
- The phishing emails used legitimate company domains and pretended to be urgent security notices requiring customer action.
- Victims reported clicking links that led to phishing websites “nearly identical” to legitimate platforms.
- CoinTracking identified the impacted email service provider as Brevo; Brevo said an attacker accessed 120 customer accounts.
- Trezor and BitBox warned customers not to click links and described efforts to take down phishing domains and investigate the incident.
Who’s being targeted
- Commonly targeted roles: All staff (phishing awareness), Finance teams handling crypto payments, IT/Service Desk (handling user reports of suspicious emails), Security team / incident response, Developers and analysts who use API keys.
- Affected industries: Cryptocurrency, Financial services, Technology/SaaS (email marketing/newsletter providers).
- Attack channels: email, website.
- Impersonated: Trezor (security team / security alert), CoinTracking (breach notification / account security).
Awareness takeaways
- Treat urgent “security alert” emails as suspicious, verify using official channels before clicking any links.
- A message can look legitimate (even from a real domain) and still be malicious if a third-party email provider is compromised.
- Be cautious of breach notices telling you to rotate secrets (passwords/API keys) via an email link, go directly to the vendor site instead.
- Report suspicious messages quickly so security teams can help take down phishing domains and warn others.
Red flags to watch for
- Unexpected urgent security alert pushing immediate action via a link
- Link leads to a site that only looks identical to the real platform
- Message is sent via a third-party newsletter system rather than normal support channels
- Pressure to take immediate action (“as soon as possible”) via an embedded link
- Breach-themed message that routes to a lookalike website
- Unexpected instruction to rotate sensitive credentials through an email link
Read the video transcript
Imagine getting this: “Critical Security Alert: STM32 Entropy Vulnerability” from Trezor. Looks legit, right? But in this breach, attackers abused Brevo’s newsletter system to send fake security emails for Trezor, CoinTracking, and BitBox, all pointing to phishing sites that look almost identical to the real platforms. Here’s the trap: the email uses real company domains, screams “refresh API keys as soon as possible,” and the link opens a site that feels perfect, logo, colors, everything, while quietly stealing your credentials. If an email says there’s a breach or wallet bug and tells you to click a link, don’t. Go to the site yourself or app you normally use, and check your account from there.