Skip to main content
Emerging ThreatsData Breaches

Trezor Phishing Attacks Target 347,000 Users After Brevo Breach

Person looks concerned while checking laptop in home office with natural daylight.
"On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts. An unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's," the company said.

Trezor's containment: scale, takedown, and immediate impact

Trezor reported that roughly 347,000 email addresses from its opt-in newsletter database were exposed to the phishing campaign that followed the Brevo incident. The company said it suspended its Brevo account to stop further distribution. According to Trezor, the malicious domain used in the campaign was taken offline within 20 minutes of detection, which limited the direct impact; the company says 2,500 customers clicked the embedded malicious link before the domain was disabled.

The phishing lure: a "critical security alert" and an STM32 claim

Customers targeted in the campaign told Trezor they received emails appearing to come from help@trezor.io marked as a "critical security alert." The messages claimed a "hardware microcontroller vulnerability" in Trezor cold storage wallets' STM32 microcontrollers could expose users' seeds to brute-force cracking. The phishing emails attempted to direct recipients to download an app that then asked them to enter their wallet backup — a classic social-engineering attack designed to harvest credentials or recovery material.

Brevo breach mechanics and exposure

In its statement Trezor described the Brevo incident as an unauthorized access to Brevo's system that affected 120 Brevo accounts and was used to send emails from various customer accounts, including Trezor's. The company emphasized that no other Trezor systems were touched in the Brevo incident, and that the exposure was limited to its opt-in newsletter database of roughly 347,000 addresses — which it warned "might be potentially used for other phishing attacks in the future."

Related customer data incidents: ShipMonk and the January 2024 support portal breach

Trezor's Brevo disclosure arrives amid a string of prior third-party compromises the company has already acknowledged. Last month, Trezor disclosed a data breach at ShipMonk, its logistics and shipping provider, after attackers exploited a critical Metabase SQL injection zero-day vulnerability and stole customers' order data including full names, shipping addresses, email addresses, and phone numbers. Trezor initially said the ShipMonk incident affected nearly 14,000 customers; a follow-up investigation expanded the count, finding an additional 67,000 U.S. customers were impacted, bringing the U.S. total to 81,000 individuals. The company said customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026, were also affected.

In January 2024, Trezor disclosed another breach after its third-party support ticketing portal was hacked and attackers stole data — including names, usernames, and email addresses — from roughly 66,000 users. BleepingComputer also reported that ShipMonk received extortion emails from the ShinyHunters extortion gang following the breach.

What this means for end users, technologists, and logistics partners

  • End users: Individuals on Trezor's opt-in newsletter list face continued phishing risk. The emails in this campaign specifically sought wallet backups by offering a fabricated security fix; users who clicked the link and entered sensitive recovery information were exposed.
  • Technologists and security teams: Security teams must account for the downstream risk posed by third-party marketing platforms. Brevo's compromise allowed an attacker to send legitimate-looking emails from customer accounts, showing how access to marketing tools can be abused to impersonate trusted brands at scale.
  • Logistics and service providers: The ShipMonk episode and the January 2024 ticketing-portal breach underline that breaches at fulfillment and support vendors can surface names, addresses, and contact details that facilitate follow-on phishing and extortion campaigns, including direct targeting and resale of data.

Trezor's statement frames the Brevo incident as a contained but consequential example of third-party risk: 347,000 newsletter addresses exposed, a malicious domain taken down in under half an hour, and 2,500 users who clicked before containment. The company has warned these email addresses "might be potentially used for other phishing attacks in the future," leaving the central practical question in this record: how organizations and customers will monitor and harden the channels — particularly marketing and fulfillment partners — that attackers repeatedly exploit to bypass perimeter controls.

Original story