
347,000 Trezor Users Hit by Phishing via Brevo Breach
A breach at email provider Brevo exposed 347,000 Trezor newsletter emails; 2,500 users clicked a phishing link that asked for wallet backups.
Trezor phishing attacks have exposed 347,000 email addresses after a breach at Brevo, the company's third-party email provider, and affected 2,500 users who clicked a malicious link before it was disabled, the company warned on Wednesday.
The phishing messages were designed to look like a critical security alert. According to customers who received them, the emails came from help@trezor.io and claimed that a 'hardware microcontroller vulnerability' in the STM32 microcontrollers used inside Trezor cold storage wallets could expose their seed phrases to brute-force cracking. A hardware wallet is a small physical device that keeps cryptocurrency private keys offline, away from internet-connected computers, so a warning about its chip immediately looks serious. The fake alert told recipients to click a link and download an app that then asked them to enter their wallet backup, which is the secret list of words that controls a cryptocurrency wallet and lets anyone who has it take the funds. Trezor says its team took down the domain used in the phishing attacks within 20 minutes, which disabled the link and limited the campaign's impact to 2,500 customers who had already clicked it.
Trezor explained that on September 9, 2026, Brevo suffered a security incident affecting 120 Brevo accounts. An unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's. The incident affected Trezor's opt-in newsletter database, roughly 347,000 email addresses, and no other Trezor system was touched. Trezor suspended the Brevo account to stop further email distribution and warned that the exposed addresses might be used for other phishing attempts in the future. A third-party email provider is an outside company a business hires to manage its marketing and newsletter messages, so a compromise there can give attackers a credible channel for sending fake emails under a well-known brand name.
This is not the first time Trezor customers have been caught up in a breach at a partner. In January 2024, Trezor disclosed another data breach after its third-party support ticketing portal was hacked and attackers stole data, including names, usernames, and email addresses, from roughly 66,000 users. Last month, Trezor also disclosed a data breach after threat actors hacked ShipMonk, its logistics and shipping provider, using a critical Metabase SQL injection zero-day vulnerability. That attack stole customers' order data, including full names, shipping addresses, email addresses, and phone numbers. Trezor initially said the incident affected nearly 14,000 customers, but a follow-up investigation found that an additional 67,000 U.S. customers were affected, bringing the total to 81,000 individuals. The company said the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026. Since then, BleepingComputer learned that ShipMonk received extortion emails from the ShinyHunters extortion gang following that breach. A zero-day vulnerability is a flaw that the software maker does not yet know about, so no fix exists when attackers begin using it. SQL injection is a technique in which an attacker submits harmful database commands through an entry form to steal or change data.
For website owners, businesses, and IT teams, the Trezor and Brevo incident is a reminder that email lists and customer data often flow through third-party services, and those vendors can become the weakest link. Phishing campaigns built on a real brand and a real breach are much harder for recipients to spot than ordinary spam. The combination of a stolen opt-in list, a spoofed sender name, and a fake security alert is exactly the kind of message that leads people to hand over account credentials or, in this case, wallet backups. Organizations can reduce this risk by reviewing which third parties can send email on their behalf, monitoring for unusual campaign activity, and enforcing strict authentication for outgoing mail. For businesses that want independent help tightening vendor access and security processes, AEU-I provides security-first IT, infrastructure and consulting. The practical lesson is straightforward: no legitimate wallet or security team will ever ask you to type your seed phrase into an app.
How to Protect Yourself
- If you receive an email claiming to be a security alert about a wallet or account, do not click any link or download any app; go to the company's official website by typing the address yourself.
- Never type your wallet backup or secret recovery words into any website or app, no matter how official it looks; no legitimate company will ever ask for them.
- Check the sender's email address carefully and compare it with the official address on the company's verified support page before you trust anything in the message.
- If you already clicked a suspicious link or entered your wallet backup, move any funds to a new wallet using a clean, trusted device and contact the company's official support.
- Turn on two-factor authentication for your email account, which means you also need a one-time code from your phone when you log in.
Terms Explained
- phishing A type of online scam where an email or website pretends to be a trusted company to trick you into giving away sensitive information.
- hardware wallet A small physical device that keeps your cryptocurrency private keys offline, away from internet-connected computers.
- seed phrase (wallet backup) A list of secret words that restores access to a cryptocurrency wallet; anyone who gets it can control the funds.
- third-party email provider An outside company that a business hires to send its marketing or newsletter emails.
- opt-in newsletter database A list of email addresses belonging to people who chose to receive newsletters.
- microcontroller A small computer chip inside a hardware device that handles its core functions.
- zero-day vulnerability A security flaw that is unknown to the software maker and therefore has no fix available when attackers start using it.
- SQL injection A technique where an attacker enters harmful database commands into a form or field to steal or change data.