Trezor Phishing Attack Targets 347,000 Users After Brevo Breach
Sep 14, 2026
A breach at third-party email provider Brevo allowed threat actors to send convincing phishing emails to hundreds of thousands of Trezor users, attempting to steal cryptocurrency wallet backups.
Incident Details | Information |
|---|---|
Target | Trezor newsletter subscribers |
Attack Type | Phishing attack |
Third-Party Provider | Brevo |
Users Targeted | Approximately 347,000 |
Users Who Clicked Malicious Link | Approximately 2,500 |
Phishing Lure | Fake critical security alert about an STM32 vulnerability |
Attacker Goal | Steal cryptocurrency wallet backups |
Trezor Systems Affected | No Trezor wallet, product, or account systems were compromised |
Response | Malicious domain taken down within approximately 20 minutes |
Trezor Users Targeted Following Brevo Security Incident
Hardware cryptocurrency wallet maker Trezor has revealed that approximately 347,000 users were targeted in a large-scale phishing campaign following a security incident at Brevo, a third-party email marketing platform used by the company.
The attackers gained access to Brevo's systems and used that access to send phishing emails from compromised customer accounts, including Trezor's newsletter account.
According to Trezor, the incident affected its opt-in newsletter database containing roughly 347,000 email addresses. While Trezor's own systems were not compromised, the incident gave attackers an opportunity to impersonate the company and send highly convincing phishing messages to its subscribers.
Fake Security Alert Used to Trick Victims
The phishing emails were designed to create urgency by warning recipients about a supposed security issue affecting Trezor hardware wallets.
One of the phishing messages used the subject line:
"Critical Security Alert: STM32 Entropy Vulnerability"
The emails falsely claimed that a vulnerability in STM32 microcontrollers used in Trezor devices could put users' cryptocurrency wallets at risk.
Recipients were encouraged to click a malicious link and download an application. The application then attempted to convince victims to enter their wallet backup information.
For cryptocurrency users, revealing a wallet backup or recovery information can have severe consequences. An attacker who obtains the necessary recovery credentials may be able to gain control of the victim's cryptocurrency assets.
Around 2,500 Users Clicked the Malicious Link
Trezor said it responded quickly after discovering the phishing campaign.
The company disabled the malicious domain at the DNS level within approximately 20 minutes, preventing the phishing link from continuing to operate.
However, around 2,500 recipients had already clicked the malicious link before the domain was taken down.
Trezor said it suspended its Brevo account to prevent additional unauthorized email distribution and contacted affected newsletter subscribers to warn them about the incident.
The company emphasized that clicking the link alone did not necessarily result in the loss of funds. The primary danger was for users who entered their wallet backup information into the malicious application or website.
Third-Party Breach Creates a Trusted Phishing Channel
This incident demonstrates one of the biggest challenges in modern phishing attacks: attackers do not always need to create fake sender identities.
When threat actors compromise a legitimate third-party platform, they may be able to abuse trusted infrastructure to distribute malicious emails.
Because Brevo was a legitimate email provider used by Trezor for newsletter communications, messages sent through the compromised account could appear more credible to recipients than traditional phishing emails sent from obviously suspicious domains.
The attack highlights the risks associated with third-party services that have access to customer communications and contact databases.
Trezor stated that no other company systems were affected and that the incident was limited to its newsletter email infrastructure. However, the company warned that the exposed email addresses could potentially be used in future phishing campaigns.
Brevo Incident Affected Multiple Accounts
According to reports on the incident, the attackers gained unauthorized access to multiple Brevo customer accounts.
The attack was linked to a flaw involving Brevo's handling of SAML Single Sign-On (SSO) access. Security reports indicated that the issue allowed attackers to gain access beyond the organization where their SSO configuration had been established.
Brevo later reported that 138 customer accounts were accessed, with some accounts used to distribute phishing emails and contacts exported from others.
The broader incident also affected other organizations in the cryptocurrency industry, demonstrating how the compromise of a shared service provider can create a widespread phishing risk across multiple companies and their customers.
Trezor Faces Another Third-Party Security Incident
The Brevo incident comes after other recent security incidents involving third-party providers connected to Trezor.
In January 2024, Trezor disclosed a breach involving a third-party support ticketing portal that exposed data associated with approximately 66,000 users.
More recently, the company also disclosed a separate breach involving ShipMonk, a logistics and shipping provider. That incident exposed customer order information, including personal details for affected customers.
The series of incidents highlights an important cybersecurity reality: an organization's security can be affected by vulnerabilities or compromises involving vendors, service providers, and other third parties.
Even when a company's core infrastructure remains secure, attackers may target external providers that handle customer data, communications, support services, or logistics.
How Users Can Protect Themselves From Similar Phishing Attacks
The Trezor phishing campaign offers several important lessons for cryptocurrency users and organizations.
Never Share Wallet Recovery Information
Cryptocurrency wallet backups and recovery information should never be entered into a website, application, or form simply because an email requests it.
Trezor has warned users that it will not contact customers asking them to provide their wallet backup.
Do Not Trust Urgency Alone
Attackers frequently use urgent language such as:
Critical security alert
Immediate action required
Your account is at risk
Security vulnerability detected
Urgency is designed to make recipients act before they carefully evaluate the message.
Verify Security Alerts Independently
Instead of clicking links in an unexpected security email, users should visit the company's official website or application independently.
This reduces the risk of being redirected to a phishing website controlled by attackers.
Be Careful With Legitimate-Looking Emails
A message can appear to come from a legitimate company and still be malicious.
Compromised email accounts, third-party platforms, and trusted communication infrastructure can all be abused by attackers to make phishing campaigns more convincing.
Third-Party Risk Is Also a Human Security Risk
The Trezor incident shows why phishing awareness cannot focus only on identifying poorly written emails or suspicious sender addresses.
Modern phishing attacks increasingly abuse:
Legitimate email platforms
Compromised third-party services
Trusted sender domains
Real company infrastructure
Urgent security warnings
Fear-based social engineering
When an attacker uses a legitimate communication channel, traditional phishing indicators may be much harder for users to identify.
Organizations need to combine strong third-party security practices with continuous cybersecurity awareness and realistic phishing simulations that prepare employees and users for attacks that closely resemble real-world threats.
Conclusion
The phishing campaign targeting 347,000 Trezor users demonstrates how a breach at a third-party service provider can quickly become a large-scale social engineering attack.
By compromising Brevo's infrastructure, attackers were able to exploit a trusted communication channel and send phishing emails designed to steal cryptocurrency wallet backups.
Trezor's rapid response limited the campaign, with the malicious domain taken down within approximately 20 minutes. However, around 2,500 users had already clicked the phishing link before it was disabled.
The incident is a reminder that phishing attacks are evolving beyond obviously fake emails. As attackers increasingly compromise trusted platforms and legitimate communication channels, users must remain cautious, verify unexpected security alerts independently, and never disclose sensitive credentials or wallet recovery information through links received in emails.






