Trezor Brevo Breach Exposes 347,000 Emails
Trezor says phishing after a Brevo email provider breach hit 347,000 addresses and 2,500 users who clicked a malicious link.
Phishing emails began landing in Trezor customers' inboxes this week, and the hardware wallet maker has now put numbers on the damage. According to the company, attackers reached 347,000 email addresses and 2,500 users clicked an embedded malicious link before the campaign was cut off.
The messages were sent to customers who had opted in to receive newsletters, the company said, after threat actors breached Brevo, its third-party email provider.
Inside the phishing emails
Customers who received the messages described fake "critical security alert" emails arriving from help@trezor.io. The emails claimed a "hardware microcontroller vulnerability" in Trezor cold storage wallets' STM32 microcontrollers could expose seeds to brute-force cracking.
The messages pushed recipients toward a malicious link, which prompted them to download an app and then asked them to enter their wallet backup. Trezor said it took the domain used in the phishing attacks down within 20 minutes, disabling the link and limiting the campaign's impact to the 2,500 customers who had clicked it before it was taken down.
Trezor's account of the Brevo incident
The company attributed the source of the campaign to a breach at its newsletter platform. "On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts. An unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's," the company said.
"The incident affected our opt-in newsletter database, roughly 347,000 email addresses. These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched. We have suspended the Brevo account to stop further email distribution."
— Trezor, in its statement on the incident
A familiar pattern of third-party breaches
The incident is not the first time Trezor has disclosed a breach tied to a vendor. In January 2024, Trezor disclosed another data breach after its third-party support ticketing portal was hacked and attackers stole data, including names, usernames, and email addresses, from roughly 66,000 users.
Trezor also disclosed a data breach after threat actors hacked ShipMonk, its logistics and shipping provider, using a critical Metabase SQL injection zero-day vulnerability, and stole customers' order data, including full names, shipping addresses, email addresses, and phone numbers.
While Trezor initially said the incident affected nearly 14,000 customers, a follow-up investigation found that the resulting breach affected an additional 67,000 U.S. customers, bringing the total to 81,000 individuals.
That incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
BleepingComputer also learned that ShipMonk received extortion emails from ShinyHunters following the breach.
The scale of the exposed data
- 347,000 email addresses affected
- 2,500 users clicked the malicious link
- 120 Brevo accounts affected
- 20 minutes — time to take down the phishing domain
What Trezor has said it did
Trezor said it suspended the Brevo account to stop further email distribution and took down the phishing domain within 20 minutes. In its statement, the company said no other Trezor system was touched.
The company also said the incident affected its opt-in newsletter database, roughly 347,000 email addresses, and warned that those addresses might potentially be used for other phishing attacks in the future.
The source material does not describe additional remediation steps beyond the domain takedown and the account suspension.
What remains unclear
The source material does not include a statement from Brevo, nor does it detail how the unauthorized actor gained access to the Brevo accounts. It also does not specify whether any regulatory notifications have been made.
What is documented is the timeline: the Brevo incident is dated September 9, 2026, and Trezor's warning came on Wednesday, according to the source.
Why it matters
For Trezor customers, the practical risk is follow-on phishing: the company itself said the exposed addresses might be used in future attacks. Anyone who clicked the link but did not enter a seed phrase should treat further messages with suspicion, and anyone who did enter a backup should consider the wallet compromised.
For the wider hardware-wallet market, the case illustrates a recurring dependency problem. Trezor's own systems were not breached in this incident, but a marketing vendor held the contact list, and that list became the attack surface. Companies that outsource customer communications inherit that risk, and their users absorb the consequences when a partner is compromised.
Sources
- BleepingComputer Original source
Continue Reading
Artifactory Flaws Chained Into Admin Backdoors
Wiz reports attackers chained two Artifactory token flaws to seize admin control and plant backdoors, while a third flaw was exploited separately.
Play Early Access Apps Hide a Deception Problem
Bitdefender says Google Play's Early Access program is being used to push fake casino and reward apps that offer no public reviews to warn users.
Patch-Gap Zero-Days Fueled BlueMoon Kit
A new exploit kit chains four Chrome and Windows flaws, revealing how quickly attackers weaponize the delay between open-source fixes and stable browser patches.