TechDogs-"Trezor Says 347,000 Subscribers Targeted In Brevo Phishing Attack, 2,500 Clicked Malicious Link"

Cyber Security

Trezor Says 347,000 Subscribers Targeted In Brevo Phishing Attack, 2,500 Clicked Malicious Link

By Amisha Dash

Updated on Fri, Sep 11, 2026

Overall Rating

Trezor says roughly 347,000 newsletter subscribers were targeted with phishing emails after attackers compromised third-party email provider Brevo, with about 2,500 people clicking the malicious link before Trezor disabled the associated domain within 20 minutes.

The cryptocurrency hardware wallet maker stressed that its wallets, products and account systems were not breached. However, users who entered their wallet backup into the fraudulent application could be at risk of losing their funds.

 

TL;DR

 
  • Around 347,000 Trezor newsletter subscribers received a fraudulent security alert following the Brevo incident.
  • Approximately 2,500 people clicked the malicious link before Trezor blocked the domain.
  • Brevo reportedly identified unauthorized access to 138 customer accounts, with six used for phishing.
  • Trezor says users who entered their wallet backup should immediately move their funds to a new wallet.
 

What Happened To Trezor Users?

 

Trezor revealed the incident in its official, saying Brevo suffered a security incident that allowed an unauthorized actor to send emails through customer accounts, including Trezor's.

The phishing email was sent to roughly 347,000 opt-in newsletter subscribers under the subject line “Critical Security Alert: STM32 Entropy Vulnerability.”

Recipients were directed to a malicious link containing an application that asked them to enter their wallet backup. Trezor warned that providing this information could allow attackers to gain control of the associated cryptocurrency wallet.

Trezor disabled the malicious domain at the DNS level within 20 minutes. However, around 2,500 people had already clicked the link before it stopped working.

The company has since contacted all 347,000 recipients and suspended its Brevo account to prevent further malicious emails.

 

Was Trezor Itself Breached?

 

No, according to Trezor.

In its official phishing incident safety guidance, the company said the breach occurred at Brevo and did not affect Trezor's products, wallets or account systems.

Trezor also said its Brevo environment contained newsletter email addresses but no passwords or cryptocurrency wallet information.

The company could not initially confirm whether its complete subscriber list had been exported. As a precaution, it is treating all roughly 347,000 addresses as potentially known to the attacker and reusable in future phishing campaigns.

Clicking the phishing link alone does not mean a user's cryptocurrency has been compromised, Trezor added. The critical risk applies to people who entered their wallet backup into the malicious application.

“If you have entered your wallet backup in any form,” Trezor said, users should move their funds to a new wallet immediately.

 

Brevo Breach Affected More Companies

 

The incident extended beyond Trezor.

According to Brevo login flaw investigation details, Brevo's postmortem said an attacker exploited a flaw involving its login and single sign-on controls to access 138 customer accounts.

Of those accounts, six were reportedly used to send phishing emails, while contacts were exported from 43 accounts. Brevo said 93 accounts showed no meaningful activity, although it did not clarify whether those categories overlapped.

Hardware wallet company BitBox and cryptocurrency portfolio and tax platform CoinTracking were also affected by fraudulent emails sent through Brevo accounts.

The reported figure is broader than Trezor's initial disclosure, which referred to an incident affecting 120 Brevo accounts. This appears to reflect updated information from Brevo's subsequent investigation rather than a separate incident.

Why The Phishing Emails Looked Legitimate

 

The Brevo compromise gave the attackers an important advantage: the fraudulent messages could be distributed using legitimate email infrastructure.

That made the messages more convincing than conventional phishing emails originating from obviously suspicious domains and could help them pass normal email authentication checks.

The attackers further strengthened the deception by presenting the email as an urgent hardware vulnerability affecting the STM32 microcontrollers used in Trezor devices.

However, the supposed vulnerability notice was fake.

BleepingComputer also detailed the campaign in its report on Trezor phishing attacks, noting that the messages attempted to convince victims their wallet seeds could be exposed to brute-force attacks.

 

Trezor Faces Another Third-Party Incident

 

The Brevo incident comes shortly after another third-party security issue affected Trezor customers.

In August, attackers compromised shipping and logistics provider ShipMonk and accessed customer order information, including names, shipping addresses, email addresses and phone numbers.

The number of affected customers was later expanded to around 81,000, including an additional 67,000 U.S. customers whose data Trezor said should previously have been deleted from ShipMonk's systems.

For Trezor customers, the latest incident reinforces one particularly important rule: legitimate wallet providers should never require users to enter their wallet backup through an email link or online form.

Anyone who entered their backup following the Brevo phishing email should create a new wallet and transfer their funds immediately.

First published on Fri, Sep 11, 2026

Enjoyed what you read? Great news – there’s a lot more to explore!

Dive into our content repository of the latest tech news, a diverse range of articles spanning introductory guides, product reviews, trends and more, along with engaging interviews, up-to-date AI blogs and hilarious tech memes!

Also explore our collection of branded insights via informative white papers, enlightening case studies, in-depth reports, educational videos and exciting events and webinars from leading global brands.

Head to the TechDogs homepage to Know Your World of technology today!

Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.

Loading comments...

  • Dark
  • Light