2,500 people clicked in twenty minutes, and we now know how the attacker got in
Yesterday we covered the phishing that went out through Brevo's own mail system to customers of Trezor, BitBox and CoinTracking. Both companies have now published figures, and they are worth sitting with for a moment.
Trezor's Brevo account held roughly 347,000 opt-in newsletter addresses. All 347,000 received the fake "Critical Security Alert: STM32 Entropy Vulnerability" message. About 2,500 people clicked the link before Trezor took the domain down at DNS level, twenty minutes after the mail started moving. Clicking was not itself the disaster, since the page then asked you to download an app and type in your wallet backup and that is where the money actually goes, but 2,500 clicks in twenty minutes is a fair measure of what a well-built phishing email does when it turns up from an address that passes every authenticity check going.
Brevo has since explained the entry route, and it is mundane enough to be unsettling. The attacker created their own Brevo account, switched on single sign-on, and invited legitimate Brevo users into it. When those invitations were accepted an authorisation boundary gave way, and the attacker could reach every organisation those invited people had access to. The count has moved from the 120 accounts reported on the day to 138 in total: six were used to send phishing, contact lists were exported from 43 others, and 93 showed nothing meaningful. Access was fully closed at 11:30 CEST on 10 September.
Trezor is now treating all 347,000 addresses as known to the attacker and likely to be reused, which is the sensible assumption for anyone who was on that list. Expect the next attempt to be better targeted. If you did click and download something, the thing to check is what is now installed: Tendvane's safety check for unwanted software lists the programs and browser add-ons sitting on your PC, including the ones that arrived without a proper introduction.