The digital financial ecosystem and the crypto-asset industry are facing a surge in sophisticated attacks targeting third-party vendors and authentication processes. Recently, user data security was severely compromised at several major industry players following incidents occurring just days apart. These breaches highlight a critical systemic vulnerability: the fraudulent exploitation of official communication channels to impersonate trusted organizations and deceive both businesses and their customers.

The first incident stems from the hacking of the email delivery platform Brevo, used by crypto industry specialists such as Trezor, BitBox, and CoinTracking. By compromising 138 client accounts, the attackers were able to export the contact lists of 43 of them and send malicious emails directly from the legitimate infrastructure. Benefiting from valid authentication protocols (SPF, DKIM, DMARC), these phishing messages were virtually undetectable. Nearly 347,000 subscribers to the Trezor newsletter received a deceptive alert prompting them to provide their recovery phrase, leading approximately 2,500 individuals to click on the malicious link before it was neutralized.

In parallel, the neobank Revolut fell victim to a highly elaborate institutional identity theft. Believing they were responding to a legitimate request from a public authority sent from an official domain with valid certificates, the fintech firm transmitted complete KYC (Know Your Customer) files. The compromised data includes identity documents, selfies, proof of address, bank statements, and bitcoin transaction history. This targeted attack appears to have primarily focused on high-net-worth profiles.

These events underscore the extreme danger posed by the aggregation of personal data. When a physical address, verified identity, and digital asset holdings are combined, criminals possess formidably precise profiling. For cryptocurrency holders, the consequences now go beyond simple cybercrime: the correlation between real-world identity, geolocation, and virtual wealth directly exposes victims to risks of extortion, burglary, or physical assault. Consequently, the management of data privacy by third parties has become a critical matter of physical security.