Brevo disclosed that hackers obtained a hardcoded, full-permission Cloudflare API key and used it to deploy a rogue Cloudflare Worker that rewrote content at the CDN edge for roughly 5.5 hours on September 14. The tampered scripts, including Brevo's forms widget, Conversations tool and SDK loader embedded on customer sites, were altered to serve ClickFix malware while stripping security headers to evade detection.
bleepingcomputer.com
· 2026-09-17
Trezor disclosed that hackers who compromised 138 accounts at email marketing provider Brevo used the access to send roughly 347,000 phishing emails to its customers. The messages, disguised as security alerts, directed recipients to a fake app designed to steal their wallet backup passwords. Trezor says its own products and account systems were not breached, but the stolen credentials could let attackers drain victims' crypto holdings.
techcrunch.com
· 2026-09-11
Trezor disclosed that a breach at its third-party email provider Brevo let attackers send fake security alerts to its opt-in newsletter subscribers, reaching roughly 347,000 email addresses. The fraudulent messages warned of a fake microcontroller vulnerability and pushed recipients to a malicious app requesting wallet backup phrases; Trezor says 2,500 people clicked the link before it disabled the domain within 20 minutes.
bleepingcomputer.com
· 2026-09-11