Trezor Scrambles to Contain Phishing Campaign After Brevo Email Provider Breach
A staggering 347,000 Trezor customers have been targeted in a recent wave of phishing attacks, with 2,500 users falling prey to malicious emails sent from compromised email accounts. The campaign, which exploited the security breach at third-party email provider Brevo, highlights the vulnerability of even the most secure systems when their supporting infrastructure is compromised.
The phishing scam, which began on September 9th, 2026, saw threat actors sending fake “critical security alert” emails to Trezor customers who had opted in to receive newsletters. The messages claimed that a hardware microcontroller vulnerability in Trezor cold storage wallets’ STM32 microcontrollers could expose users’ seeds to brute-force cracking. Recipients were tricked into clicking on an embedded link, which prompted them to download an app and enter their wallet backup.
Trezor’s swift response to the incident saw the company take down the phishing domain within 20 minutes of becoming aware of it. This move limited the campaign’s impact, but not before 2,500 users had clicked on the malicious link. The compromised email accounts used in the attack were reportedly Brevo’s customer accounts, which had been accessed by an unauthorized actor.
The breach at Brevo has sent shockwaves through the cybersecurity community, with Trezor warning that the affected email addresses may be used for further phishing attacks in the future. This incident is just the latest in a string of security breaches affecting Trezor customers. In January 2024, the company disclosed another data breach after its third-party support ticketing portal was hacked, compromising around 66,000 users’ personal data.
Trezor’s reliance on Brevo for newsletter campaigns has also raised concerns about the risks associated with using third-party services in sensitive industries like cryptocurrency storage. The incident highlights the importance of robust security measures and vigilant monitoring to prevent such attacks from succeeding.
As users, it is essential to remain cautious when interacting with emails that claim to be from reputable sources but ask for sensitive information. Verify the authenticity of any links or requests by contacting the company directly through official channels. By staying informed and taking proactive steps to protect ourselves, we can minimize the impact of such attacks and maintain our digital security.
To mitigate this risk, users should always approach emails with a healthy dose of skepticism, especially when they ask for sensitive information like wallet backups. Verify the authenticity of any links or requests by contacting Trezor directly through official channels. By being vigilant and proactive in protecting ourselves, we can minimize the impact of such attacks and maintain our digital security.
Source: Bleeping Computer — 2026-09-11