Trezor Confirms Brevo Email Provider Breach Leading to Phishing Attack on 347,000 Users

Here's what it means for you.
If you’re a cryptocurrency user, this incident underscores the importance of vigilance against phishing attacks, even from trusted brands.
Why it matters
This breach highlights systemic vulnerabilities in third-party service dependencies within the cryptocurrency sector.
What happened (in 30 seconds)
- On September 9, 2026, Trezor confirmed a breach at its email provider Brevo, impacting 347,000 newsletter subscribers.
- Phishing emails were sent from Trezor's domain, misleading users into downloading a malicious application.
- No customer wallet data was compromised, but the incident follows a prior data exposure at Trezor's shipping partner, ShipMonk.
The context you actually need
- Trezor is a leading hardware wallet provider that relies on third-party services for email marketing and shipping.
- The breach exploited a flaw in SAML SSO authentication, allowing unauthorized access to customer accounts and enabling phishing attacks.
- Previous incidents, like the August 2026 breach at ShipMonk, have already raised concerns about data security in the cryptocurrency hardware sector.
What's really happening
On September 9, 2026, Trezor detected unauthorized phishing emails sent through its Brevo account, targeting approximately 347,000 subscribers. The emails, which appeared legitimate, contained a fabricated subject line warning of a "Critical Security Alert: STM32 Entropy Vulnerability." This tactic aimed to instill urgency and prompt users to download a malicious application that requested sensitive wallet backup credentials.
Brevo confirmed that attackers accessed 138 accounts, with six accounts actively used for phishing and 43 for exporting contact lists. Trezor acted quickly, suspending the compromised account and disabling the phishing domain within minutes, limiting the number of clicks to around 2,500. Despite the rapid response, the incident underscores the risks associated with third-party service dependencies, particularly in the cryptocurrency sector, where trust is paramount.
The breach follows a previous incident in August 2026, where Trezor's shipping partner, ShipMonk, exposed personal data of nearly 14,000 customers. This pattern of breaches raises questions about the security protocols of third-party providers and the potential for cascading failures in the cryptocurrency ecosystem.
While Trezor has reassured customers that no wallet data was compromised, the incident has heightened awareness of phishing risks among cryptocurrency users. Similar phishing campaigns have targeted other crypto firms using Brevo's infrastructure, such as BitBox and CoinTracking, indicating a broader vulnerability in the sector.
As the investigation continues, Trezor has issued direct notifications to affected customers and published FAQs to clarify the situation. Brevo has also provided an incident status update detailing the SAML SSO flaw that enabled the breach. The market impact appears limited, with no significant price movements or regulatory actions reported as of September 12, 2026. However, the incident serves as a stark reminder of the importance of cybersecurity vigilance in an increasingly interconnected digital landscape.
Who feels it first (and how)
- Cryptocurrency users: Increased risk of phishing attacks targeting their wallets.
- Trezor customers: Heightened anxiety over the security of their personal data and assets.
- Third-party service providers: Scrutiny over their security measures and potential loss of client trust.
What to watch next
- User vigilance: Monitor how cryptocurrency users adapt their security practices in response to this incident.
- Regulatory scrutiny: Watch for any potential regulatory responses aimed at improving third-party security standards in the cryptocurrency sector.
- Market reactions: Observe any shifts in consumer trust and market dynamics among hardware wallet providers following this breach.
The breach involved unauthorized access to Brevo accounts and phishing emails sent to Trezor subscribers.
Increased scrutiny on third-party service providers in the cryptocurrency sector will lead to enhanced security measures.
The long-term impact on user trust in Trezor and similar hardware wallet providers remains to be seen.
Frequently Asked Questions
- Why it matters?
- This breach highlights systemic vulnerabilities in third-party service dependencies within the cryptocurrency sector.
- What happened (in 30 seconds)?
- On September 9, 2026, Trezor confirmed a breach at its email provider Brevo, impacting 347,000 newsletter subscribers. Phishing emails were sent from Trezor's domain, misleading users into downloading a malicious application. No customer wallet data was compromised, but the incident follows a prior data exposure at Trezor's shipping partner, ShipMonk.
- What's really happening?
- On September 9, 2026, Trezor detected unauthorized phishing emails sent through its Brevo account, targeting approximately 347,000 subscribers. The emails, which appeared legitimate, contained a fabricated subject line warning of a "Critical Security Alert: STM32 Entropy Vulnerability." This tactic aimed to instill urgency and prompt users to download a malicious application that requested sensitive wallet backup credentials. Brevo confirmed that attackers accessed 138 accounts, with six accou
- Who feels it first (and how)?
- Cryptocurrency users: Increased risk of phishing attacks targeting their wallets. Trezor customers: Heightened anxiety over the security of their personal data and assets. Third-party service providers: Scrutiny over their security measures and potential loss of client trust.
- What to watch next?
- User vigilance: Monitor how cryptocurrency users adapt their security practices in response to this incident. Regulatory scrutiny: Watch for any potential regulatory responses aimed at improving third-party security standards in the cryptocurrency sector. Market reactions: Observe any shifts in consumer trust and market dynamics among hardware wallet providers following this breach.
Startup news with frequent AI coverage.
"Covers launches, funding, and product updates in AI."
— A47 Editor
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
Trezor has confirmed a data breach involving its email provider, leading to scammers targeting hundreds of thousands of cryptocurrency owners. This incident marks the second breach affecting a company that Trezor relies on, raising significant concer...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Trezor phishing attack traced to Brevo login authorization flaw
A recent phishing attack has been traced back to an authorization flaw in Brevo's login system, which allowed an attacker to access 138 customer accounts. This breach resulted in phishing emails being sent from accounts associated with Trezor, BitBox...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
Brevo login flaw enabled phishing email targeting 347K Trezor subscribers
A login flaw in Brevo's email service has led to a phishing email being sent to 347,000 Trezor subscribers, raising significant security concerns. Trezor has stated that every email address involved is considered compromised and potentially reusable ...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Trezor, BitBox warn users after phishing emails target wallet holders
Hardware wallet manufacturers Trezor and BitBox have issued warnings to users about phishing emails that appear as urgent security notices, following a breach of Trezor's email provider. This incident raises concerns about the safety of wallet holder...