CuraSec

Plan active

Trezor phishing campaign via Brevo breach hits 347K users

2026-09-11 14:58 UTC · BleepingComputer · read the source ↗ #phishing#supply-chain#email-security
  • Engineer — Plan: If your org uses Brevo (Sendinblue) as an email/marketing service provider, audit your account for unauthorized access and review what customer data is stored there; this breach shows ESP compromise can expose your customer lists to targeted phishing.
  • SOC/IR — Learn: The attack chain—ESP breach leading to targeted customer phishing—is a useful lure pattern to understand, but no IOCs or ATT&CK-mappable TTPs are provided in this item to act on.
  • Leader — Learn: A clear example of third-party SaaS vendor risk: a breach at email provider Brevo exposed Trezor’s customer list and enabled downstream phishing; worth citing in vendor risk review discussions, but no immediate action required unless your org uses Brevo.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.