The Trezor phishing needed no stolen password. Brevo's SSO let the attacker sign in as the people they invited
Phishing that reached 347,000 Trezor newsletter subscribers came from Trezor's genuine Brevo account, so it passed every sender check. Brevo's post-mortem says the attacker created an account, switched on single sign-on, invited real Brevo users into it, and was then let into every organisation those users could reach. Early coverage spoke of stolen login details. Brevo's account involves none.