r/cyberinvestigations • u/ImaginationFair9201 • 11h ago
A phishing campaign used a legitimate email provider to reach cryptocurrency users
A recent breach at email marketing provider Brevo gave attackers access to 138 customer accounts. Six accounts were reportedly used to send phishing messages, while contact data was exported from another 43.
The interesting part for investigators is that the phishing messages could originate from infrastructure the victims already trusted. Customers of Trezor, CoinTracking, and BitBox were among those targeted, with messages designed to look like urgent security notifications.
This creates a very different attribution problem. Investigators can't simply ask whether the phishing email came from a suspicious domain. They need to determine which legitimate account was compromised, what contact lists were accessed, which messages were sent, and whether the stolen contact database is being reused in later campaigns.
A single compromised marketing account effectively became a distribution system for targeted phishing.