← BACK TO FEED
TAG

sso vulnerability1 article

Trezor Customers Hit by Phishing Wave After Marketing Platform Botches SSO Security

Trezor has warned approximately 347,000 customers that they received phishing emails after its third-party marketing platform, Brevo, was hacked via a SAML Single Sign-On (SSO) vulnerability that allowed an attacker to gain unauthorized access to multiple accounts. The phishing emails, titled "Critical Security Alert: STM32 Entropy Vulnerability," directed users to a malicious website where entering their wallet backup could result in lost funds; around 2,500 users clicked the link before the site was taken down within 20 minutes. This breach follows a separate recent incident in which Trezor's shipping provider ShipMonk exposed the personal data of tens of thousands of customers, raising concerns about an increased risk of targeted phishing attacks against Trezor users.

13 Sept 2026