Skip to content
Tech News
← Back to articles

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

read original get Trezor Safe 5 Hardware Wallet → more articles
Why This Matters

A breach at email marketing provider Brevo let attackers send convincing phishing emails from Trezor's own [email protected] address, exposing 347,000 newsletter subscribers and tricking 2,500 into clicking a link designed to harvest wallet seed phrases. It's another reminder that crypto hardware wallet security often fails at the vendor's third-party supply chain rather than the device itself, and that legitimate sender addresses can no longer be treated as proof of authenticity.

Key Takeaways
Worth a Look

Trezor Safe 5 Hardware Wallet — If phishing emails have you rethinking how your crypto keys are stored, the Trezor Safe 5 keeps private keys offline on a dedicated device with on-screen confirmation for every action — so a fake "security alert" link can't quietly move your funds. It's the current flagship from Trezor, with a color touchscreen that makes verifying addresses and PINs straightforward. Remember: no legitimate email will ever ask you to type your recovery seed.

See Trezor Safe 5 Hardware Wallet on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link.

As Trezor warned on Wednesday, threat actors who breached Brevo, its third-party email provider, were emailing customers who opted in to receive newsletters.

According to customers targeted in this phishing campaign, they received fake "critical security alert" emails from [email protected] claiming that a "hardware microcontroller vulnerability" in Trezor cold storage wallets' STM32 microcontrollers could expose their seeds to brute-force cracking.

The phishing emails tried to trick recipients into clicking a malicious link that prompted them to download an app that asked them to enter their wallet backup.

Trezor says that it took down the domain used in the phishing attacks within 20 minutes, disabling the link and limiting the campaign's impact to 2,500 customers who had clicked it before it was taken down.

"On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts. An unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's," the company said.

"The incident affected our opt-in newsletter database, roughly 347,000 email addresses. These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched. We have suspended the Brevo account to stop further email distribution."

Trezor phishing email (Geo Soul)

In January 2024, Trezor disclosed another data breach after its third-party support ticketing portal was hacked and attackers stole data (including names, usernames, and email addresses) from roughly 66,000 users.

Trezor also disclosed a data breach last month after threat actors hacked ShipMonk, its logistics and shipping provider, using a critical Metabase SQL injection zero-day vulnerability, and stole customers' order data, including full names, shipping addresses, email addresses, and phone numbers.

... continue reading