Brevo says attackers breached its email platform and used six customer accounts to send phishing mail to subscribers of multiple crypto firms, including Trezor, BitBox, and CoinTracking. The company says 138 accounts were breached and contacts were exported from 43 of them.
The trick was not spoofing the brands from scratch. The attackers sent messages through the real newsletter system those companies already used, so the mail arrived from legitimate brand infrastructure and looked convincing enough that some recipients clicked through to fake sites.
For any organization that outsources newsletters or customer updates, the exposure sits in the shared provider and the trust it holds, not just in one brand account. A compromise there can fan out across unrelated customer bases at once, and the cleanup burden includes both account security and the credibility damage of mail that looked authentic.