Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

A Phishing Campaign Hits 347,000 Trezor Users After Brevo Hack

Trezor, a leading provider of cold cryptocurrency storage solutions, has announced that approximately 347,000 of its customers received phishing emails after a third-party marketing platform it uses was hacked. The incident highlights the dangers of data breaches and the importance of secure practices for users.

The compromised platform is called Brevo, which Trezor employs to send newsletters to its customers. An attacker exploited how Brevo handles Single Sign-On (SSO) authentication to access 138 accounts on the platform. What’s concerning is that the breach was not limited to just those accounts; the attacker gained access to all organizations tied to the users they had invited, essentially granting them carte blanche to access sensitive data.

Using this access, the threat actor sent phishing messages to email addresses stored in six of the compromised Brevo accounts. One such account belonged to Trezor itself. The phishing emails had a subject line that read “Critical Security Alert: STM32 Entropy Vulnerability” and included a link pointing to a malicious website. The attackers’ intention was to trick users into entering their wallet backup, potentially leading to fund loss.

Fortunately, only 2,500 users clicked on the link before the malicious site was taken offline just 20 minutes after the incident was detected. However, it’s unclear how many users may have lost funds and to what extent. This incident follows a recent data breach affecting nearly 14,000 people, which exposed their personal information through Trezor’s third-party shipping provider ShipMonk.

Trezor customers are likely to be targeted by phishing attacks in the coming days and weeks, making it essential for users to remain vigilant about suspicious emails. BitBox, another cryptocurrency hardware wallet maker, and CoinTracking, a crypto tax calculator, also appear to have been affected by the Brevo hack, although they haven’t shared details on the impact.

As we’ve seen time and again, data breaches can have far-reaching consequences beyond just exposing sensitive information. They often serve as stepping stones for attackers to launch targeted campaigns against users of compromised services. In this case, Trezor customers are advised to be cautious about emails from unknown senders and never enter their wallet backup or other sensitive credentials in response to unsolicited requests.

To stay safe online, it’s essential for individuals to adopt secure practices such as enabling two-factor authentication (2FA), keeping software up-to-date, and being wary of suspicious communications. By taking these precautions, users can minimize the risk of falling victim to phishing attacks like this one.


Source: SecurityWeek — 2026-09-11