Phishing Campaign Targets Trezor Customers After Brevo Email Provider Breach

Here's what it means for you.
If you're a Trezor user, this phishing incident highlights the critical need for vigilance in protecting your cryptocurrency assets.
Why it matters
This breach underscores the vulnerabilities inherent in third-party vendor relationships, particularly in the cryptocurrency sector.
What happened (in 30 seconds)
- On September 9, 2026, scammers exploited a breach at Brevo, Trezor's email provider, sending phishing emails to 347,000 subscribers.
- The emails falsely warned of a fabricated vulnerability in Trezor devices and directed users to download a malicious app.
- Trezor confirmed that its systems were unaffected and has since suspended its Brevo account while reevaluating vendor relationships.
The context you actually need
- Third-party risks: Hardware wallet providers like Trezor rely on external vendors for services, creating vulnerabilities that can expose customer data without compromising their core systems.
- Recent breaches: This incident follows an August 2026 breach at Trezor's shipping partner, ShipMonk, which exposed data of at least 81,000 customers, leading to further phishing attempts.
- Rising attacks: The cryptocurrency sector is experiencing an increase in targeted attacks, including phishing and physical "wrench" attacks that leverage leaked personal data.
What's really happening
On September 9, 2026, unauthorized actors accessed Brevo accounts through a flaw in the SAML Single Sign-On (SSO) system. This breach allowed them to send phishing emails that appeared to originate from Trezor's legitimate newsletter infrastructure, specifically from the domain mailing.trezor.io. The emails passed SPF, DKIM, and DMARC checks, making them look credible to recipients.
The phishing emails were titled "Critical Security Alert: STM32 Entropy Vulnerability" and claimed a factory defect affecting one in four Trezor devices. They included a link to a malicious app that requested users' wallet recovery phrases, posing a significant risk of irreversible fund loss on public blockchains. Trezor quickly responded by posting warnings on social media and its blog, confirming that the breach affected its opt-in newsletter database of approximately 347,000 addresses.
Brevo reported that access was gained to 138 accounts, with six accounts used for phishing and 43 for contact exports. Trezor acted swiftly, suspending the Brevo account and blocking the domain within minutes of discovering the breach. However, approximately 2,500 clicks occurred on the phishing links before mitigation efforts were implemented.
This incident is particularly concerning as it highlights the ongoing risks associated with third-party vendor relationships in the cryptocurrency space. The reliance on external providers for essential services like email marketing and shipping creates a supply-chain risk where breaches can expose customer data without compromising the core wallet systems.
Moreover, the incident follows a troubling trend of increasing targeted attacks on cryptocurrency users. The combination of phishing attempts and physical attacks, such as "wrench" attacks, indicates a growing sophistication among cybercriminals. As the cryptocurrency market continues to expand, so too does the potential for exploitation by malicious actors.
Who feels it first (and how)
- Trezor customers: Approximately 347,000 newsletter subscribers are at risk of phishing attacks.
- Cryptocurrency users: Broader implications for all users of hardware wallets as phishing attempts become more sophisticated.
- Vendors and partners: Companies relying on third-party services may face increased scrutiny and risk management challenges.
What to watch next
- Increased phishing attempts: Monitor for a rise in phishing campaigns targeting Trezor users and other cryptocurrency wallet customers.
- Vendor relationship evaluations: Watch for Trezor's actions regarding its vendor partnerships and any changes in their security protocols.
- Regulatory responses: Keep an eye on potential regulatory changes in the cryptocurrency sector aimed at enhancing security measures for third-party vendors.
Trezor's systems were not compromised; phishing emails were sent from Brevo accounts.
Increased scrutiny on third-party vendor security in the cryptocurrency sector.
The long-term impact on Trezor's customer trust and potential financial losses from phishing attacks.
Frequently Asked Questions
- Why it matters?
- This breach underscores the vulnerabilities inherent in third-party vendor relationships, particularly in the cryptocurrency sector.
- What happened (in 30 seconds)?
- On September 9, 2026, scammers exploited a breach at Brevo, Trezor's email provider, sending phishing emails to 347,000 subscribers. The emails falsely warned of a fabricated vulnerability in Trezor devices and directed users to download a malicious app. Trezor confirmed that its systems were unaffected and has since suspended its Brevo account while reevaluating vendor relationships.
- What's really happening?
- On September 9, 2026, unauthorized actors accessed Brevo accounts through a flaw in the SAML Single Sign-On (SSO) system. This breach allowed them to send phishing emails that appeared to originate from Trezor's legitimate newsletter infrastructure, specifically from the domain mailing.trezor.io. The emails passed SPF, DKIM, and DMARC checks, making them look credible to recipients. The phishing emails were titled "Critical Security Alert: STM32 Entropy Vulnerability" and claimed a factory def
- Who feels it first (and how)?
- Trezor customers: Approximately 347,000 newsletter subscribers are at risk of phishing attacks. Cryptocurrency users: Broader implications for all users of hardware wallets as phishing attempts become more sophisticated. Vendors and partners: Companies relying on third-party services may face increased scrutiny and risk management challenges.
- What to watch next?
- Increased phishing attempts: Monitor for a rise in phishing campaigns targeting Trezor users and other cryptocurrency wallet customers. Vendor relationship evaluations: Watch for Trezor's actions regarding its vendor partnerships and any changes in their security protocols. Regulatory responses: Keep an eye on potential regulatory changes in the cryptocurrency sector aimed at enhancing security measures for third-party vendors.
Startup news with frequent AI coverage.
"Covers launches, funding, and product updates in AI."
— A47 Editor
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
Trezor has confirmed a data breach involving its email provider, leading to scammers targeting hundreds of thousands of cryptocurrency owners. This incident marks the second breach affecting a company that Trezor relies on, raising significant concer...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Trezor phishing attack traced to Brevo login authorization flaw
A recent phishing attack has been traced back to an authorization flaw in Brevo's login system, which allowed an attacker to access 138 customer accounts. This breach resulted in phishing emails being sent from accounts associated with Trezor, BitBox...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
Brevo login flaw enabled phishing email targeting 347K Trezor subscribers
A login flaw in Brevo's email service has led to a phishing email being sent to 347,000 Trezor subscribers, raising significant security concerns. Trezor has stated that every email address involved is considered compromised and potentially reusable ...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
Trezor, BitBox warn users about fake hardware wallet security alerts
Trezor and BitBox have issued warnings to users about fraudulent security alerts related to hardware wallets, indicating that multiple Bitcoin companies were targeted through a shared newsletter provider. Trezor confirmed a breach at its email servic...