Cointelegraph reported that the phishing email incident that occurred the previous day at hardware wallet companies Trezor and BitBox was confirmed to be an attack exploiting a login system flaw in Brevo, the email service provider used by both companies. The attacker accessed 138 Brevo customer accounts, sending phishing emails from 6 of them. Similar emails were also sent from the cryptocurrency tax platform CoinTracking. Approximately 347,000 people received phishing emails from Trezor, and about 2,500 people accessed malicious links. Trezor blocked the domain in about 20 minutes and advised users to be careful, stating that newsletter email addresses could be exploited for further phishing.