Your customers could lose crypto in a phishing scam – is your email provider the weak link?

Hook: A phishing wave that could hit any small business
Imagine receiving an email that looks exactly like a message from your own brand, urging a customer to click a link and enter a password. For crypto owners, that mistake can mean the loss of all their funds in a single click. That is what happened after a breach at a marketing‑email provider used by hardware‑wallet maker Trezor. Even if you never sell crypto, the same vulnerability exists for every business that relies on a third‑party service to send newsletters, invoices or promotional offers.
In this article we’ll explain why the breach matters to you and give a short checklist you can start using today to make sure your email communications are not the weak link in your security chain.
Breach recap: What happened at Brevo
- The supplier: Brevo (formerly known as Sendinblue) provides the email‑marketing platform that Trezor uses to send newsletters to its customers.
- The attack: Hackers gained access to 138 Brevo accounts. Because the platform’s permission model was mis‑configured, the attackers could reach every organization linked to those accounts.
- The phishing campaign: About 347 000 emails were sent that appeared to come from Trezor. One subject line read “Critical Security Alert: STM32 Entropy Vulnerability.” The email contained a link that downloaded a fake app asking for the wallet’s backup password.
- The impact: With the password, a criminal can move the victim’s crypto assets permanently. Trezor confirmed that none of its hardware or internal systems were compromised, but the incident shows how a breach at a vendor can be used to impersonate a brand at scale.
Why it matters to any small business
1. Your brand can be spoofed at scale
When a vendor that sends your emails is compromised, attackers can use your brand’s name, logo and tone to trick recipients. Your customers trust the “from” address, so a phishing email that looks legitimate is far more likely to be opened.
2. Financial loss isn’t limited to crypto
Even if you don’t deal with digital currencies, a successful phishing attack can lead to stolen credit‑card details, fraudulent invoice payments, or the installation of ransomware on your own systems.
3. Reputation damage is immediate
A single successful scam that appears to come from your business can erode trust, cause customers to switch to competitors, and generate negative word‑of‑mouth that is hard to repair.
Email security checklist for small businesses
Below is a short, practical list you can start implementing this week. No need for deep technical expertise—just a few clear steps and the right partner to help you.
1. Secure your email domain with authentication protocols
- DMARC (Domain-based Message Authentication, Reporting & Conformance) tells receiving mail servers how to treat messages that aren’t really from you;
- SPF (Sender Policy Framework) lists which servers are allowed to send mail for your domain;
- DKIM (DomainKeys Identified Mail) adds a digital signature that proves the email really came from you.
How to start: Ask your email‑service provider to enable DMARC, SPF and DKIM for your domain. If you manage the DNS yourself, the provider will give you the required TXT records to add.
2. Verify vendor security certifications
Before signing a contract with any third‑party service that handles customer data, request evidence of security controls—such as ISO 27001, SOC 2 Type II, or a recent penetration‑test report. Keep these documents in a central folder and review them annually.
3. Monitor for suspicious email activity
Set up alerts for unusual spikes in outbound email volume or for failed DMARC checks. Many email‑security platforms can forward a daily summary to your inbox, allowing you to spot a potential breach early.
4. Train staff to spot phishing
- Simple rule: If an email asks for a password, private key, or payment information, treat it as suspicious.
- Practice drills: Send fake phishing emails to your team once a month and discuss the clues that gave them away.
- Clear reporting channel: Provide a dedicated address (e.g., security@yourcompany.com) where employees can forward doubtful messages for verification.
5. Keep a list of third‑party services you rely on
Maintain a list of all services that store or transmit customer data (email platforms, CRM, payment gateways, cloud storage, etc.). Assign a risk rating and schedule periodic reviews. This makes it easier to spot which relationships need tighter controls.
6. Have an incident‑response plan for email‑related attacks
Define who is responsible for communicating with customers, how you will revoke compromised credentials, and what public statements you will make. Practicing the plan reduces panic and limits damage when an actual incident occurs.
FAQ
Can I protect my business if I use a free email newsletter service?
A: Yes. Even free services can add DMARC, SPF and DKIM records to your domain. They are the first line of defence against spoofed emails and are supported by most providers at no extra cost.
How often should I review my vendors’ security posture?
A: At a minimum once a year, or sooner if you hear news of a breach affecting one of your suppliers. An annual review keeps your risk inventory up to date without overwhelming you.
My staff are not very tech‑savvy. How can I make phishing training effective?
A: Keep the training short, use real‑world examples (like the Trezor/Brevo case), and focus on simple checks: look for mismatched sender addresses, hover over links before clicking, and never share passwords via email.
Next steps with IT Move NL
A compromised email provider can turn a trusted brand into a phishing launchpad in minutes. Protecting your business isn’t about buying the most expensive tools; it’s about building solid processes, verifying the security of the services you rely on, and keeping your team alert.
At IT Move NL we specialise in Security & Protection for small businesses. Our team can:
- Audit all third‑party vendors you work with
- Implement DMARC, SPF and DKIM for your domain
- Set up continuous monitoring for suspicious email activity
- Deliver hands‑on phishing‑awareness training for your staff
Don’t let a supplier’s breach become your headline. Get in touch today for a free security health check and make sure your email communications stay trustworthy.
Sources:

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent
Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.
STAY IN THE LOOP
// Cloud, AI & DevOps insights — straight to your inbox.
No spam. Unsubscribe anytime.
// Related articles
Need help with your cloud infrastructure?
Our team of experts is ready to help you navigate the complexities of modern cloud architecture.
Get in Touch

