Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

60-second summary
Trezor reports that a Brevo login vulnerability allowed attackers to harvest and target 347,000 subscriber email addresses with a crafted phishing campaign, treating each address as “known to the attacker and possibly reusable for phishing.” The breach forces users to verify credentials, heightens security scrutiny, and could pressure wallet providers to tighten email authentication across the crypto industry.
Trezor told Cointelegraph that the phishing email was sent to 347,000 subscribers and said it is treating every address as “known to the attacker and possibly reusable for phishing.”