Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Trezor customers targeted in massive phishing campaign after email provider Brevo is breached, exposing nearly 350,000 email addresses.

A major cybersecurity incident has unfolded for Trezor users this week, with threat actors taking advantage of a breach in the company’s third-party email provider, Brevo. The attack, which was swiftly contained by Trezor, saw phishing emails sent to an astonishing 347,000 email addresses, affecting around 2,500 customers who clicked on malicious links.

The scheme, which aimed to trick users into divulging their wallet backups, exploited a perceived vulnerability in Trezor’s cold storage wallets. However, it appears this “vulnerability” was entirely fabricated, and the actual goal was to harvest sensitive information from unsuspecting victims. The phishing emails were cleverly crafted to appear as if they came directly from Trezor’s support team, complete with a convincing email address (help@trezor.io) and an urgent message claiming that users’ seeds could be exposed to brute-force cracking.

Trezor’s swift response to the incident was critical in limiting the damage. The company took down the malicious domain within 20 minutes, disabling the phishing link and preventing further harm. However, the fact remains that nearly 350,000 email addresses were exposed as a result of the Brevo breach, leaving them vulnerable to future phishing attacks.

This is not Trezor’s first brush with data breaches and security incidents. In January 2024, the company disclosed a breach affecting around 66,000 users after its third-party support ticketing portal was hacked. More recently, in August, Trezor announced another breach after threat actors exploited a critical vulnerability in ShipMonk, its logistics provider, to steal customers’ order data.

The combination of these incidents highlights the importance of vigilance and proactive security measures for companies that rely on third-party services. Brevo’s breach serves as a stark reminder that even seemingly secure systems can be compromised by determined threat actors. As we navigate an increasingly complex cybersecurity landscape, it is essential to stay informed about potential threats and take immediate action when incidents occur.

If you’re a Trezor user, the takeaway from this incident is clear: remain vigilant and skeptical of unsolicited emails, especially those claiming urgent security alerts or asking for sensitive information. Verify the authenticity of any messages by contacting Trezor directly through trusted channels, rather than clicking on links or downloading attachments. By staying proactive and informed, you can protect yourself against phishing attacks and other cybersecurity threats.


Source: Bleeping Computer — 2026-09-11