Trezor Reports Fresh Breach After Phishing Campaign Hits Marketing Vendor

Trezor warns of phishing after a breach at its email vendor Brevo exposed 347,000 customers.

10/09/2026 21:427 min read

Trezor has alerted users that a security incident at its external newsletter provider is enabling scammers to launch phishing attacks against its customers.

The leading hardware wallet maker disclosed on Wednesday that an attacker broke into Brevo's systems, which then transmitted emails to 347,000 Trezor users. Brevo is a service firms rely on for customer messaging.

The email was sent using Trezor's own domain, adding credibility to the fraudulent message. Inside was a dangerous link that prompted recipients to install an application and provide their wallet seed phrase.

Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.

We have taken down the domain, and we are investigating…

— Trezor (@Trezor) September 9, 2026

This development follows Trezor's disclosure last month that 11,742 clients' data was compromised when its logistics partner ShipMonk was hit.

The company then reported a week ago that a further 67,000 U.S. customers had names, email addresses, phone numbers, shipping details and order IDs exposed in that incident.

“We took down the domain at the DNS level within 20 minutes, preventing the link from working for anyone else and limiting access to 2,500 people who had clicked it before we took it down,” Trezor said on Wednesday.

“These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched,” Trezor added.

“We have suspended the Brevo account to stop further email distribution.”

Trezor reiterated that it never solicits wallet backups from customers.

This year fraudsters have been exploiting data, obtaining client details via crypto wallet provider Ledger's payment processor Global-e to dispatch phishing messages.

Crypto wallet firm SafePal also disclosed a breach last month that exposed around 39,798 customers' order details, comprising personal information including names, addresses and purchase history.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles