VMTech
Discuss a project

Brevo breach used to send 347,000 phishing emails to Trezor users

Brevo breach used to send 347,000 phishing emails to Trezor users

Trezor has warned customers that attackers used a breach at Brevo, the marketing technology provider it uses for newsletters, to send roughly 347,000 phishing emails impersonating the hardware wallet maker. The campaign directed recipients to a malicious link that downloaded an app requesting the backup password for a crypto wallet.

One reported subject line was “Critical Security Alert: STM32 Entropy Vulnerability.” Trezor said that possession of a wallet backup password can enable an attacker to steal funds irreversibly on a public blockchain. The company said its products, wallets and account system were not affected by the incident.

Brevo access crossed organizational boundaries

Brevo said attackers accessed 138 Brevo accounts to send the phishing messages at scale. In its incident status update, the company said a flaw meant the attackers’ access was not properly scoped and was wrongly granted to all organizations reachable by the compromised accounts.

The episode illustrates a third-party security risk: a service provider used for a necessary customer function can become the channel through which attackers reach a company’s users. In this case, the attackers did not need to compromise Trezor’s wallet infrastructure to distribute a credential-stealing lure under the Trezor name.

A second vendor incident affecting Trezor customers

The Brevo incident is the second recent vendor-related breach to affect Trezor customers. A compromise at shipping partner the ShipMonk customer data breach exposed contact and delivery information, including names, phone numbers, email addresses and postal addresses, for at least 81,000 people who bought and received Trezor hardware.

After that incident, some recipients reported postal letters claiming to be from Trezor. Those letters included QR codes leading to fraudulent pages intended to obtain crypto wallet passwords. The exposed delivery and contact data can also increase the risk of targeted physical coercion, sometimes described as wrench attacks.

Customer communications need stronger controls

Trezor said it is reassessing its vendor relationships and warned that customer email addresses may be used in future phishing attempts. The warning reflects the lasting value of contact data to attackers: even after a single campaign is identified, those details can support new email, mail or other impersonation attempts.

For businesses that rely on external communications, fulfilment or marketing providers, the practical implication is to review vendor access boundaries and prepare customers with clear rules for recognising official messages. Customers should independently verify security alerts and never provide wallet backup passwords to an app, website, email or QR-code destination.

#cybersecurity#phishing#cryptosecurity#vendorrisk
Open analytics
On the site 1 views
min read 3 11.09.2026
Instagram

Brevo breach used to send 347,000 phishing emails to Trezor users

Open the post on Instagram ↗