Find notable cyber news and cases, enriched with sources, timelines, and signals.

Brevo-abused Trezor security-alert phishing campaign

Campaign
First reported
Last updated
Happening score
H score 45
1 unique sources, 1 articles

Summary

Hide ▲

A Brevo-abused phishing campaign targeted Trezor newsletter subscribers with fake security-alert emails, reaching 347,000 email addresses and driving 2,500 clicks before takedown.

Related Happenings

ShipMonk hit by network compromise

Incident
H score43 First: 13.08.2026 18:13 Last: 13.08.2026 18:13 Sources 1

About this happening: Trezor says an August ShipMonk breach now affects 81,000 customers after an additional 67,000 U.S. customers were exposed when ShipMonk did not delete customer dat...

Trezor customers customer data exposed after ShipMonk breach

Data Leak
H score44 First: 13.08.2026 18:13 Last: 13.08.2026 18:13 Sources 1

About this happening: A ShipMonk breach exposed Trezor customer order data for 11,742 fully exposed records and 1,947 partially exposed records, increasing the risk of phishing and impe...

Latest development: 05.09.2026 17:17

Trezor said another 67,000 U.S. customers were impacted in a breach at its shipping provider ShipMonk, with exposed information including customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The exposure adds to earlier customer records already disclosed and does not affect the security of Trezor hardware wallets.

Kali365 Microsoft 365 device-code phishing campaign

Campaign
H score46 First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

About this happening: A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...

Latest development: 05.08.2026 14:43

Kali365 uses device-code phishing to target US organizations, presenting lures that impersonate SharePoint, OneDrive, or DocuSign before redirecting victims to Microsoft's legitimate device login portal for attacker-provided codes; successful approvals can yield access and refresh tokens with continued access to Microsoft 365 email, documents, and cloud resources, and ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week.

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Timeline

  1. 11.09.2026 10:55 1 articles · 1h ago

    Brevo account compromise enables phishing email abuse

    Initial Disclosure

    Brevo suffered a security incident on September 9, 2026 after an unauthorized actor gained access to its system and used various customer accounts, including Trezor's newsletter account, to send emails. The incident affected 120 Brevo accounts.

    Show sources
  2. 11.09.2026 10:55 2 articles · 1h ago

    Trezor newsletter subscribers hit by fake security-alert phishing emails

    Campaign Scope Update

    Trezor customers who opted in to newsletters received fake "critical security alert" emails from [email protected] claiming that a "hardware microcontroller vulnerability" in Trezor cold storage wallets' STM32 microcontrollers could expose their seeds to brute-force cracking. The phishing campaign targeted 347,000 email addresses, affected 2,500 users who clicked the malicious link, and the domain used in the attacks was taken down within 20 minutes; Trezor also suspended the Brevo account to stop further email distribution.

    Show sources