The scam email came from the company's real mailing list
Every piece of advice about spotting a phishing email leans on the same idea: something about it will look wrong. Wrong sender address, wrong domain, a header that fails a check. On 10 September a campaign went out that failed none of those tests, because it was sent through the companies' own mailing systems.
Brevo, the email marketing service formerly called Sendinblue, confirmed that an attacker gained access to 120 Brevo customer accounts and used them to send phishing to the contact lists sitting inside. Brevo says the unauthorised access was fully closed at 11:30 CEST on 10 September. Among the businesses whose lists were used: the hardware wallet makers Trezor and BitBox, and the crypto tax service CoinTracking.
The messages were tailored. Trezor customers got one headed "Critical Security Alert: STM32 Entropy Vulnerability", BitBox customers a near-identical "Critical Security Alert: Microcontroller Entropy Bug Identified", both claiming a factory defect had left their device with critically low 40-bit randomness and inviting them to enter their wallet backup to check. That backup is the wallet. CoinTracking users, who may not own a hardware device at all, were sent "Data Breach Notice: Please refresh API Keys as soon as possible" instead. Trezor's response was short: do not click it, and never enter your wallet backup anywhere. It comes days after the company was already dealing with customer data taken from a logistics partner.
You do not need to own a crypto wallet for this to matter. Most shops, banks and services you deal with send their newsletters through a provider like Brevo, and when one of those accounts is taken over the email that reaches you is genuinely from the company's mail system. The habit that still holds is refusing to act inside an email at all: if a message says your account needs attention, open a new tab and go to the site yourself. Tendvane's Privacy and accounts check gives you the list of accounts your PC is signed into and how each one is protected, which is a useful thing to have in front of you when you are not sure whether a warning was real.