Third-Party Email Breach Hits Trezor Newsletter Subscribers
Hardware wallet maker Trezor has disclosed that a breach at its email marketing vendor, Brevo, allowed attackers to hijack its newsletter account and send phishing emails to 347,000 addresses. Trezor says 2,500 users clicked the embedded malicious link before the company shut the campaign down.
What Happened
On September 9, 2026, Brevo suffered a security breach that compromised 120 of its customer accounts, exploiting an authentication vulnerability that gave attackers unauthorized entry into at least 138 accounts, including Trezor's. Other cryptocurrency-adjacent companies using Brevo — including BitBox and CoinTracking — were compromised through the same vendor breach.
Attackers used Trezor's hijacked Brevo account to send phishing emails to the full list of 347,000 subscriber addresses. The emails falsely warned recipients of a hardware microcontroller vulnerability in Trezor devices and urged them to download an app that, if installed, was designed to capture wallet backup seed phrases — the private keys that control access to a user's cryptocurrency holdings.
Trezor's Response
Trezor says it detected the campaign quickly and took the phishing domain down within 20 minutes, while also suspending its Brevo account to stop further distribution. Despite the rapid response, the company confirmed that approximately 2,500 recipients clicked the malicious link before takedown.
What Data Was Exposed
Trezor clarified the scope of what lived in its Brevo account: exclusively opt-in newsletter email addresses, with no authentication credentials, private keys, or other personal details stored on the platform. However, out of caution, Trezor is treating all 347,000 affected addresses as potentially exposed to follow-on phishing attempts.
Trezor emphasized that no other company systems were compromised — the incident was confined to the third-party newsletter database.
Other Companies Affected
- BitBox confirmed the malicious email reached subscribers on both its newsletter and educational-tutorial mailing lists via Brevo, but found no evidence of contact-database downloads, stolen funds, or compromised seed phrases — only email addresses and language preferences were stored in Brevo.
- CoinTracking had its compromised Brevo account used to send a message falsely titled "Data Breach Notice: Please refresh API Keys as soon as possible," itself a phishing lure.
A Pattern of Vendor-Related Incidents
This is not Trezor's first security incident tied to a third-party vendor. The company has previously dealt with breaches involving its support ticketing portal and its logistics provider, ShipMonk. In response to this latest incident, Trezor says it is conducting a comprehensive audit of its third-party service providers and strengthening vendor security requirements across the board.
Why This Matters
Hardware wallet vendors like Trezor sell trust as much as they sell devices — their entire security model depends on users never entering a seed phrase anywhere but their own hardware. A phishing email that appears to come from a legitimate, previously-trusted Trezor mailing list is far more effective than a cold phishing attempt, because it inherits the sender's credibility. This incident is a reminder that an organization's security posture is only as strong as its weakest connected vendor — a marketing email platform, of all things, became the delivery mechanism for a seed-phrase theft campaign against a hardware security company.
Recommendations
For Trezor Newsletter Subscribers
- Do not click links in emails claiming a Trezor hardware or microcontroller vulnerability — verify any security notice directly at trezor.io
- Never enter your recovery seed phrase into any app, website, or device other than your physical Trezor hardware wallet
- If you clicked the phishing link or entered any wallet information, move funds to a new wallet with a freshly generated seed immediately
- Report suspicious Trezor-branded emails to Trezor's official support channels
For Organizations Using Third-Party Email/Marketing Platforms
- Enforce strong authentication (MFA, SSO) on all marketing and email-automation platform accounts
- Limit the data stored in third-party marketing tools to the minimum necessary — Trezor's restraint in only storing opt-in emails limited the blast radius here
- Have an incident playbook for vendor-side breaches, including rapid domain takedown and customer notification procedures
- Audit vendor security postures on a recurring basis, not only after an incident occurs
Source: BleepingComputer