TTO-2026-0911-116 · September 11, 2026 Third-Party BreachPhishing

Brevo SAML SSO Flaw Exploited to Send 347,000 Trezor Phishing Emails — 2,500 Clicked Before Domain Takedown

brevo.comSAML SSO flaw347,000 Trezor subscribers targeted2,500 clickedSTM32 entropy lureDomain taken down in 20 minutes

Summary

Attackers exploited a flaw in Brevo's SAML single sign-on configuration to gain unauthorized access to 120 Brevo accounts on September 9, 2026, including Trezor's newsletter account. They used that access to send phishing emails to approximately 347,000 Trezor newsletter subscribers, impersonating Trezor and claiming a critical hardware vulnerability in STM32 microcontrollers could expose wallet seed phrases to brute-force attack. Trezor identified the campaign, took down the phishing domain within 20 minutes, and suspended its Brevo account. Approximately 2,500 users clicked the malicious link before the domain was removed. No Trezor systems other than the Brevo newsletter account were affected. This is the third distinct vendor-related security incident affecting Trezor documented by this outlet in 2026, following TTO-2026-0905-106 and TTO-2026-0907-108.

Timeline

DateEvent
Sep 9, 2026Attacker exploits Brevo SAML SSO flaw, compromises 120 Brevo customer accounts including Trezor's; sends phishing emails to 347,000 Trezor subscribers
Sep 9, 2026Trezor identifies campaign, takes down phishing domain within 20 minutes, suspends Brevo account
Sep 9, 2026Trezor posts public warning: STM32 Entropy Vulnerability email is a phishing attempt
Sep 11, 2026Trezor discloses 347,000 addresses targeted; 2,500 users confirmed clicked; Brevo publishes SSO root-cause analysis

What Happened

The Brevo breach originated in how the platform handles SAML single sign-on. An attacker created a Brevo account, enabled SSO on it, and invited legitimate Brevo users into the compromised setup. By operating their own identity provider within the SSO flow, the attacker gained access to accounts associated with the invited users, including Trezor's newsletter account. Brevo confirmed 120 accounts were affected, with contact data from 43 accounts extracted and phishing emails sent from six affected accounts.

The phishing email was sent from the legitimate [email protected] address, passing email authentication checks because it was dispatched through Brevo's own infrastructure under Trezor's account. The email claimed a flaw in STM32 microcontrollers used in Trezor cold storage wallets could expose recovery seed phrases to brute-force cracking, and directed recipients to download an application that requested their wallet backup. Trezor considers all 347,000 newsletter addresses now known to the attacker and potentially reusable in future phishing campaigns.

Domain Intelligence

brevo.com — 61.74

Score sits in the low-trust range. Brevo is the breached party in this incident — the email marketing platform whose SAML SSO implementation contained the flaw that enabled the attack. One threat intelligence source has flagged brevo.com but the observation has not been independently corroborated; per WarmBadge's methodology, an unconfirmed single-source flag does not reduce the published score on its own.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 11, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026