Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 6 sources · 7 days · First seen · Last updated
Brevo platform security breach and supply-chain attack
Overview
A security breach at the marketing platform Brevo evolved from a targeted phishing campaign into a widespread supply-chain attack.
Initially, attackers exploited a vulnerability in Brevo’s SAML single sign-on system to gain unauthorized access to approximately 138 customer accounts. This allowed them to export contact lists from 43 accounts, which were used to launch phishing attacks against cryptocurrency-related companies. For example, Trezor reported that attackers used Brevo’s legitimate infrastructure to send fraudulent emails regarding a supposed hardware vulnerability, affecting roughly 347,000 subscribers. Other firms, including Solana Mobile, BitBox, and CoinTracking, were also targeted.
In a subsequent phase, the attack expanded significantly. After the initial breach was blocked, attackers returned using a compromised, highly privileged Cloudflare API key. This allowed them to deploy a malicious Cloudflare Worker to inject code at the CDN edge, potentially affecting over 100,000 websites. This method enabled attackers to rewrite web responses and remove security headers without modifying Brevo’s origin servers. The attack attempted to distribute “ClickFix” scripts and install unauthorized plugins on WordPress sites.
Entities
Brevo · Trezor · Sansec · WordPress · Solana Mobile
Timeline
-
11 days ago
[TECHNOLOGY] 3 sourcesBrevo supply-chain attack infects over 100,000 websitesA supply-chain attack on Brevo used a compromised Cloudflare API key to inject malware into over 100,000 websites via edge-side code injection.
-
17 days ago
[TECHNOLOGY] 4 sourcesBrevo security breach triggers phishing attacks on crypto firmsA breach at marketing provider Brevo allowed attackers to access accounts of crypto firms like Trezor and Solana Mobile, launching phishing campaigns against hundreds of thousands of subscribers.
Sources
coinedition.com · cybernoz.com · detlionblood32.wordpress.com · dev.to · itnerd.blog · world-today-journal.com