search

LEMON BLOG

Trezor Says 347,000 Users Were Targeted After Brevo Breach Triggered Phishing Campaign

Trezor has disclosed new details about a phishing campaign that targeted hundreds of thousands of its customers after attackers compromised Brevo, the third-party marketing platform used to send the company's newsletters. According to Trezor, roughly 347,000 email addresses were exposed to the campaign, while around 2,500 users clicked the malicious link before the phishing infrastructure was taken offline.

The incident is another reminder that even when a company's core systems remain secure, attackers can still reach customers by compromising trusted suppliers. In this case, the breach did not originate from Trezor's wallet infrastructure, but from an external email service that had legitimate access to its communications workflow. That gave the attackers a particularly convincing way to impersonate Trezor and make their messages appear authentic.

Phishing Emails Warned About a Fake Hardware Vulnerability

The malicious emails were designed to create panic. Recipients reportedly received what appeared to be an urgent security warning from This email address is being protected from spambots. You need JavaScript enabled to view it., claiming that a serious vulnerability had been discovered in the STM32 microcontrollers used in Trezor hardware wallets.

The message alleged that the supposed flaw could expose wallet seeds to brute-force attacks, creating the impression that customers needed to act immediately to protect their cryptocurrency. That kind of technical language can be highly persuasive because it sounds specific, credible and closely related to the product being used.

Victims were encouraged to click a link and download an application that supposedly helped secure their wallet. In reality, the software prompted users to enter their wallet backup, which could then potentially give attackers control over the associated cryptocurrency holdings.

For hardware wallet users, this is one of the most dangerous types of phishing attempt. The wallet itself may remain secure, but if a user voluntarily provides their recovery phrase or backup credentials to an attacker, those protections can effectively be bypassed.

Trezor Says the Malicious Domain Was Disabled Within 20 Minutes

Trezor says it reacted quickly after becoming aware of the phishing campaign. The company reportedly managed to have the malicious domain taken down within approximately 20 minutes, preventing additional customers from accessing the fraudulent website.

By the time the link was disabled, however, around 2,500 people had already clicked it. Clicking the link alone does not necessarily mean those users lost funds or entered their recovery information, but it means they were exposed to the next stage of the attack and may require additional caution.

The rapid takedown likely reduced the overall impact considerably. Phishing campaigns often depend heavily on a short window of opportunity, especially when they are distributed through an apparently legitimate sender and use urgent language intended to push people into acting before they stop to verify the message.

The Breach Originated From Trezor's Email Marketing Provider

Trezor said the underlying incident occurred on September 9, 2026, when Brevo suffered a security compromise affecting 120 customer accounts. An unauthorised actor reportedly gained access to Brevo's system and used that access to send messages through several customer accounts, including Trezor's.

Because Brevo was already authorised to send legitimate newsletters on Trezor's behalf, messages sent through the compromised service had a much better chance of appearing trustworthy. This is what makes supply-chain-style attacks so difficult to defend against: the attacker does not always need to break into the primary company directly if a trusted vendor provides another route.

Trezor said the incident affected its opt-in newsletter database, which contained around 347,000 email addresses. The company has since suspended its Brevo account to prevent further messages from being distributed through the service.

The Email Addresses Could Still Be Used in Future Attacks

Even though the immediate phishing domain was taken down quickly, the incident may continue to create risks for customers. Trezor warned that the exposed email addresses could potentially be reused in future phishing campaigns.

That means affected users should remain cautious about any unexpected email claiming to come from Trezor, especially messages involving urgent security warnings, firmware issues, wallet recovery procedures or requests to verify a seed phrase.

Attackers often reuse stolen contact information long after the original breach. In some cases, email addresses are combined with data from other breaches to build more convincing profiles of potential victims. A future phishing message might therefore appear unrelated to the Brevo incident while still relying on information obtained from it.

For cryptocurrency users, this is particularly important because attackers know that successful social engineering can lead directly to valuable digital assets.

Trezor Says Its Core Systems Were Not Compromised

One important distinction in the incident is that Trezor says no other internal systems were affected. The compromise was limited to the Brevo-based newsletter database rather than the company's hardware wallet platform or core infrastructure.

That does not make the incident harmless, but it changes the nature of the risk. The attackers did not reportedly gain direct access to customers' wallets or automatically obtain recovery seeds. Instead, they attempted to trick users into voluntarily surrendering that information.

This difference is significant because hardware wallets are built around the idea that sensitive private keys remain protected from remote attacks. Social engineering, however, attacks the human rather than the hardware. If a user is persuaded to reveal a recovery phrase, even the strongest wallet security cannot undo that mistake.

Trezor Has Faced Other Third-Party Breaches Before

This is not the first time Trezor customers have been affected by a security incident involving an external provider. In January 2024, the company disclosed a breach involving its third-party support ticketing system.

Attackers reportedly accessed data belonging to approximately 66,000 users, including names, usernames and email addresses. As with the latest incident, the breach did not directly compromise Trezor hardware wallets, but the stolen contact information could still be valuable for phishing and impersonation attempts.

The repetition highlights a growing challenge for technology companies. Even if an organisation maintains strong internal security controls, it may still depend on dozens of third-party services for support, logistics, marketing, analytics and communication. Each of those relationships creates another potential attack surface.

ShipMonk Breach Exposed Customer Order Information

Trezor also disclosed another third-party breach recently involving ShipMonk, its logistics and shipping provider. Attackers reportedly compromised ShipMonk using a critical Metabase SQL injection zero-day vulnerability and gained access to customer order information.

The exposed data included full names, shipping addresses, email addresses and phone numbers. Trezor initially estimated that nearly 14,000 customers were affected, but a later investigation revealed that an additional 67,000 customers in the United States had also been impacted.

That brought the total number of affected individuals to approximately 81,000.

The company also said customers in Brazil, Colombia, Italy, Portugal, Sweden and the United Kingdom were affected if they received orders during the period between May 10 and August 8, 2026.

Why Shipping Data Can Be Particularly Sensitive for Hardware Wallet Users

A shipping breach involving a cryptocurrency hardware wallet company can carry risks beyond ordinary spam. Knowing that a particular person purchased a hardware wallet may allow criminals to infer that the individual owns or manages cryptocurrency.

When names, addresses, phone numbers and email addresses are exposed together, attackers can potentially create highly personalised scams. A fraudulent message could reference a real purchase, shipping details or other legitimate information, making it much more convincing than a generic phishing attempt.

In extreme cases, physical addresses connected to cryptocurrency ownership may also create personal security concerns. This is why customers of hardware wallet companies are often particularly sensitive about data breaches involving order and shipping records.

The ShipMonk incident therefore demonstrates how third-party data exposure can create risks even when no wallet credentials are stolen directly.

ShinyHunters Was Reportedly Linked to the ShipMonk Fallout

Following the ShipMonk breach, BleepingComputer reportedly learned that the company had received extortion emails from the ShinyHunters group. The cybercrime gang is known for targeting organisations, stealing data and attempting to pressure victims into paying to prevent further exposure.

The reported involvement adds another layer to the incident because it suggests the attackers were not necessarily interested only in accessing customer information. Stolen data can also be used as leverage against the breached organisation, creating financial and reputational pressure alongside the direct risk to affected individuals.

For customers, however, the practical concern remains the same: once personal information has been stolen, it may circulate well beyond the original breach and potentially be reused in future scams.

Third-Party Providers Are Becoming an Attractive Target

The series of incidents involving Trezor illustrates why attackers increasingly target suppliers rather than trying to breach major companies directly. A third-party service may have access to large amounts of customer data while maintaining a very different security environment from the organisation it supports.

Marketing platforms can access subscriber databases, customer support providers may hold names and email addresses, while logistics firms can possess complete delivery information. Compromising one of these suppliers can therefore provide attackers with valuable data without requiring them to defeat the security controls of the main company.

It also creates an opportunity for attackers to abuse trusted communication channels. In the Brevo incident, for example, sending messages through an authorised marketing platform likely made the phishing campaign more believable than emails originating from an obviously unrelated domain.

This makes vendor risk management increasingly important. Companies need to evaluate not only their own cybersecurity practices but also the security posture of organisations that process customer information on their behalf.

Crypto Users Need to Treat Recovery Phrases Differently From Passwords

One of the most important lessons from the campaign is that a hardware wallet recovery phrase should never be treated like a normal password. A legitimate wallet provider should not require users to type their recovery phrase into a website or application simply because an email warns of a security problem.

The recovery phrase represents the ultimate backup to a cryptocurrency wallet. Anyone who obtains it may be able to recreate the wallet elsewhere and gain access to the associated funds.

Users should therefore be extremely suspicious of any message requesting that information, regardless of how convincing the sender appears. Even if an email comes from a familiar address or references legitimate technical details, recovery credentials should never be entered simply because a message claims urgent action is required.

What Affected Customers Should Watch For

Customers whose email addresses were included in the affected newsletter database should expect that phishing attempts may continue. Attackers may change tactics, domains or messaging while continuing to target the same group of users.

Some warning signs are particularly important:

The safest approach is to avoid following links contained in suspicious emails and instead visit the official Trezor website or application directly. Any security announcement serious enough to affect hundreds of thousands of customers should also be verifiable through official channels.

Final Thoughts

The Brevo breach shows how effectively attackers can exploit trust in third-party platforms. Trezor's core wallet infrastructure was reportedly untouched, yet criminals were still able to send highly convincing security alerts to hundreds of thousands of genuine customers through a compromised marketing provider.

The speed of Trezor's response appears to have limited the immediate damage, with the malicious domain taken offline within around 20 minutes. However, the exposure of approximately 347,000 email addresses means the risk does not disappear simply because the original phishing link is no longer active.

Combined with earlier incidents involving Trezor's support and shipping providers, the situation highlights how cybersecurity increasingly extends beyond protecting internal systems. Companies must also account for the vendors that handle customer data on their behalf, while users need to remain cautious even when a message appears to come through a legitimate communication channel.

For hardware wallet owners in particular, the most important rule remains simple: never share your recovery phrase or wallet backup with anyone, and never enter it into software or websites because of an unsolicited security warning.

Ant International Brings AI-Powered Payments to TN...
Intel Brings Back One Mono After Briefly Retiring ...

Related Posts

 

Comments 0

Loading latest comments...
Monday, 14 September 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection