Trezor’s 347,000 Customers Targeted in Phishing Scam After Brevo Hack
A recent breach of a third-party marketing platform used by cryptocurrency storage provider Trezor has put nearly 350,000 of its customers at risk. The attacker exploited how Brevo handles Single Sign-On (SSO) to access 138 accounts and sent phishing messages to the email addresses stored under six of those compromised accounts.
Brevo explained that the attack worked as follows: an attacker created a Brevo account and enabled SSO on it, then invited legitimate users into that configuration. This allowed them to sign in as those invited users using their own identity provider, which is expected behavior for SSO. However, instead of being limited to the single organization where SSO was enabled, the attacker gained access to all organizations those users could reach.
The attacker sent phishing messages to 347,000 email addresses stored in one of the compromised Brevo accounts. The emails had the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and contained a link pointing to a malicious website. Trezor warned customers that clicking on the link and entering their wallet backup could result in lost funds.
While only 2,500 users clicked on the link before the malicious site was taken offline, it’s unclear how many may have fallen victim to the scam and lost money. Trezor has not shared details about the malicious website, but emphasized that its customers’ security is a top priority.
This incident is the latest in a string of security breaches affecting Trezor and its users. Just last month, the company announced that nearly 14,000 people had their personal information compromised in a data breach involving its third-party shipping provider ShipMonk. The ShipMonk leak affected an additional 67,000 US customers, including their name, email, shipping address, phone number, and order number.
The Brevo hack highlights the importance of secure authentication practices and the potential risks associated with using third-party services for marketing and other purposes. Organizations that rely on these services must ensure they are properly configured to prevent unauthorized access and data breaches.
For Trezor customers, this incident serves as a reminder to remain vigilant when receiving emails or messages claiming to be from the company or its partners. Always verify the authenticity of communications before taking any action, and never click on suspicious links or enter sensitive information unless you’re absolutely sure it’s safe to do so.
Source: SecurityWeek — 2026-09-11