Brevo login flaw let an attacker send phishing emails to 347,000 Trezor subscribers, plus BitBox and CoinTracking users.