Crypto Customers Targeted by Scammers After Email Marketing Provider Breach
Crypto Customers Targeted by Scammers 🚨
An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields. The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms.
Brevo later stated that 138 customer accounts had been accessed in its postmortem: “On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts. Six of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts, they exported the contacts.”
According to reports, popular cryptocurrency companies Trezor, CoinTracking, and BitBox confirmed that phishing emails were sent to customers subscribed to their newsletters. Trezor warned its roughly 347,000 newsletter subscribers that a security incident at a third-party provider had resulted in a massive phishing campaign. Trezor makes hardware wallets that store cryptocurrency private keys offline. Its customers received a phishing email titled “Critical Security Alert: STM32 Entropy Bug Identified.” The subtitle read: “Urgent update regarding hardware microcontroller vulnerability.” The email claimed: “Unfortunately, our engineering team has identified a critical hardware-level vulnerability in the STM32 microcontrollers used in a range of Trezor devices. The bug is a hardware factory defect present in an estimated 1 in 4 devices. The vulnerability results in: Insufficient randomness in recovery phrase generation, Exposure of seeds to brute-force cracking, Seeds with as little as 40 bits of entropy.” That phishing email also contained a link that prompted recipients to download an app and enter their wallet backup.
Additionally, CoinTracking said the attackers sent its customers an email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” which also contained a malicious link.
Because the emails came from legitimate company domains and looked convincing, some recipients may have fallen for them. It can be difficult to recognize a phishing email when it comes from a legitimate company domain and looks convincing. If a company emails you about an urgent security problem, check its official website or app for confirmation. Do not install apps through links in unsolicited emails, no matter how urgent the message claims to be. Never enter your recovery phrase anywhere other than on your physical device. Reputable companies will not ask for recovery phrases, API keys, or login details by email.
The attackers exported contacts from 43 accounts, which could be used in future targeted phishing attacks. Trezor advises moving your funds to a new wallet if you entered your wallet backup in any form. If you followed a link in a similar email from another provider, contact that company directly for advice.