Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2743+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Trezor: 347,000 Users Targeted in Phishing Attacks After Brevo Breach
Trezor: 347,000 Users Targeted in Phishing Attacks After Brevo Breach
NEWS

Trezor: 347,000 Users Targeted in Phishing Attacks After Brevo Breach

A breach at email platform Brevo let attackers hijack Trezor's newsletter account and phish 347K addresses; 2,500 users clicked the malicious link.

Dylan H.

Security Engineer

September 11, 2026
4 min read

Third-Party Email Breach Hits Trezor Newsletter Subscribers

Hardware wallet maker Trezor has disclosed that a breach at its email marketing vendor, Brevo, allowed attackers to hijack its newsletter account and send phishing emails to 347,000 addresses. Trezor says 2,500 users clicked the embedded malicious link before the company shut the campaign down.

What Happened

On September 9, 2026, Brevo suffered a security breach that compromised 120 of its customer accounts, exploiting an authentication vulnerability that gave attackers unauthorized entry into at least 138 accounts, including Trezor's. Other cryptocurrency-adjacent companies using Brevo — including BitBox and CoinTracking — were compromised through the same vendor breach.

Attackers used Trezor's hijacked Brevo account to send phishing emails to the full list of 347,000 subscriber addresses. The emails falsely warned recipients of a hardware microcontroller vulnerability in Trezor devices and urged them to download an app that, if installed, was designed to capture wallet backup seed phrases — the private keys that control access to a user's cryptocurrency holdings.

Trezor's Response

Trezor says it detected the campaign quickly and took the phishing domain down within 20 minutes, while also suspending its Brevo account to stop further distribution. Despite the rapid response, the company confirmed that approximately 2,500 recipients clicked the malicious link before takedown.

What Data Was Exposed

Trezor clarified the scope of what lived in its Brevo account: exclusively opt-in newsletter email addresses, with no authentication credentials, private keys, or other personal details stored on the platform. However, out of caution, Trezor is treating all 347,000 affected addresses as potentially exposed to follow-on phishing attempts.

Trezor emphasized that no other company systems were compromised — the incident was confined to the third-party newsletter database.

Other Companies Affected

  • BitBox confirmed the malicious email reached subscribers on both its newsletter and educational-tutorial mailing lists via Brevo, but found no evidence of contact-database downloads, stolen funds, or compromised seed phrases — only email addresses and language preferences were stored in Brevo.
  • CoinTracking had its compromised Brevo account used to send a message falsely titled "Data Breach Notice: Please refresh API Keys as soon as possible," itself a phishing lure.

A Pattern of Vendor-Related Incidents

This is not Trezor's first security incident tied to a third-party vendor. The company has previously dealt with breaches involving its support ticketing portal and its logistics provider, ShipMonk. In response to this latest incident, Trezor says it is conducting a comprehensive audit of its third-party service providers and strengthening vendor security requirements across the board.

Why This Matters

Hardware wallet vendors like Trezor sell trust as much as they sell devices — their entire security model depends on users never entering a seed phrase anywhere but their own hardware. A phishing email that appears to come from a legitimate, previously-trusted Trezor mailing list is far more effective than a cold phishing attempt, because it inherits the sender's credibility. This incident is a reminder that an organization's security posture is only as strong as its weakest connected vendor — a marketing email platform, of all things, became the delivery mechanism for a seed-phrase theft campaign against a hardware security company.

Recommendations

For Trezor Newsletter Subscribers

  1. Do not click links in emails claiming a Trezor hardware or microcontroller vulnerability — verify any security notice directly at trezor.io
  2. Never enter your recovery seed phrase into any app, website, or device other than your physical Trezor hardware wallet
  3. If you clicked the phishing link or entered any wallet information, move funds to a new wallet with a freshly generated seed immediately
  4. Report suspicious Trezor-branded emails to Trezor's official support channels

For Organizations Using Third-Party Email/Marketing Platforms

  1. Enforce strong authentication (MFA, SSO) on all marketing and email-automation platform accounts
  2. Limit the data stored in third-party marketing tools to the minimum necessary — Trezor's restraint in only storing opt-in emails limited the blast radius here
  3. Have an incident playbook for vendor-side breaches, including rapid domain takedown and customer notification procedures
  4. Audit vendor security postures on a recurring basis, not only after an incident occurs

Source: BleepingComputer

#Data Breach#Phishing#Trezor#Cryptocurrency#Supply Chain

Related Articles

14,000 Trezor Customers Impacted by Data Breach at ShipMonk

Hackers stole shipping data including names, addresses, emails, and phone numbers from 14,000 Trezor customers via a breach at logistics firm ShipMonk.

4 min read

Trezor Data Breach Impact Now Reaches 81,000 Customers

Trezor says a ShipMonk data breach via a Metabase SQLi zero-day now affects 81,000 customers, up from 14,000 in the initial disclosure.

3 min read

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Trezor confirms ShipMonk's breach exposed 67,000 more customers via old records the fulfillment partner had assured were deleted, pushing the total to ~80,689.

4 min read
Back to all News