Summary
Attackers exploited a flaw in Brevo's SAML single sign-on configuration to gain unauthorized access to 120 Brevo accounts on September 9, 2026, including Trezor's newsletter account. They used that access to send phishing emails to approximately 347,000 Trezor newsletter subscribers, impersonating Trezor and claiming a critical hardware vulnerability in STM32 microcontrollers could expose wallet seed phrases to brute-force attack. Trezor identified the campaign, took down the phishing domain within 20 minutes, and suspended its Brevo account. Approximately 2,500 users clicked the malicious link before the domain was removed. No Trezor systems other than the Brevo newsletter account were affected. This is the third distinct vendor-related security incident affecting Trezor documented by this outlet in 2026, following TTO-2026-0905-106 and TTO-2026-0907-108.
Timeline
| Date | Event |
|---|---|
| Sep 9, 2026 | Attacker exploits Brevo SAML SSO flaw, compromises 120 Brevo customer accounts including Trezor's; sends phishing emails to 347,000 Trezor subscribers |
| Sep 9, 2026 | Trezor identifies campaign, takes down phishing domain within 20 minutes, suspends Brevo account |
| Sep 9, 2026 | Trezor posts public warning: STM32 Entropy Vulnerability email is a phishing attempt |
| Sep 11, 2026 | Trezor discloses 347,000 addresses targeted; 2,500 users confirmed clicked; Brevo publishes SSO root-cause analysis |
What Happened
The Brevo breach originated in how the platform handles SAML single sign-on. An attacker created a Brevo account, enabled SSO on it, and invited legitimate Brevo users into the compromised setup. By operating their own identity provider within the SSO flow, the attacker gained access to accounts associated with the invited users, including Trezor's newsletter account. Brevo confirmed 120 accounts were affected, with contact data from 43 accounts extracted and phishing emails sent from six affected accounts.
The phishing email was sent from the legitimate [email protected] address, passing email authentication checks because it was dispatched through Brevo's own infrastructure under Trezor's account. The email claimed a flaw in STM32 microcontrollers used in Trezor cold storage wallets could expose recovery seed phrases to brute-force cracking, and directed recipients to download an application that requested their wallet backup. Trezor considers all 347,000 newsletter addresses now known to the attacker and potentially reusable in future phishing campaigns.
Domain Intelligence
brevo.com — 61.74
Score sits in the low-trust range. Brevo is the breached party in this incident — the email marketing platform whose SAML SSO implementation contained the flaw that enabled the attack. One threat intelligence source has flagged brevo.com but the observation has not been independently corroborated; per WarmBadge's methodology, an unconfirmed single-source flag does not reduce the published score on its own.
The Trust Observatory · thetrustobservatory.com · September 11, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026