Skip to main content
Security

Trezor warns of 347,000 phishing emails after Brevo breach

Trezor warns of 347,000 phishing emails after Brevo breach Image: Primary
Trezor said a cyberattack on Brevo, the marketing technology company it uses to send newsletters, let hackers send roughly 347,000 phishing emails to Trezor customers with a malicious link purporting to come from the wallet maker. Brevo said attackers accessed 138 accounts and abused a flaw that left their access "not properly scoped," wrongly granting reach across organizations. Trezor said its products, wallets and account system were unaffected. The link downloads an app that asks for the wallet backup password; a stolen password lets an attacker irreversibly take funds on the public blockchain. Trezor said it is reevaluating vendor relationships and warned addresses may be reused in future phishing.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from TechCrunch, BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

NASA and IBM release open lunar foundation model on Hugging Face

NASA and IBM Research released the NASA-IBM Lunar Foundation Model, an open-source AI model built for lunar science, hosted publicly on Hugging Face with its codebase on GitHub. NASA said the model was trained primarily on 17 yea...

Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security
Security

Wiz reports Artifactory flaw chain exploited to plant Rust backdoor

Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...