Brevo Breach Sends Trezor Phishing Email to 347,000 Subscribers

A Brevo breach allowed attackers to send Trezor phishing emails to 347,000 subscribers, exposing security risks created by trusted third-party vendors.

Sep 14, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A security warning sent through Trezor’s legitimate newsletter system turned out to be the attack itself.

Attackers exploited a breach at Brevo, the third-party email platform Trezor uses for newsletters, to send a fake alert claiming a hardware vulnerability could expose users’ wallet seeds. The email pushed recipients toward a malicious website and an application that requested their wallet backup.

The campaign reached 347,000 Trezor newsletter subscribers, and 2,500 people clicked the malicious link before Trezor intervened. The company said its products, infrastructure, and users’ cryptocurrency wallets were not compromised. However, the incident shows how breaching a trusted vendor can give attackers a direct route to a company’s audience.

How attackers weaponized legitimacy

Most phishing attacks start by obtaining a list of email addresses and then building a convincing imitation of the service they want to impersonate. In this case, the attackers skipped much of that work by compromising the legitimate email service Trezor already used to communicate with customers, then used that trusted channel to direct users toward a malicious platform.

According to Trezor, the attackers compromised its account at Brevo, one of 120 customer accounts affected at the email provider. That access allowed them to distribute the phishing message through Trezor’s legitimate newsletter channel, giving the campaign an advantage that a conventional spoofed email would not have.

The message itself was designed to create urgency. It claimed that Trezor devices were affected by a serious “STM32 Entropy Bug” that could expose users’ wallet seeds.

Brevo breach allowed attackers to send Trezor phishing emails to 347,000 subscribers.
Brevo breach allowed attackers to send Trezor phishing emails to 347,000 subscribers. Image: Trezor

The legitimate delivery channel made the campaign especially dangerous. Rather than merely impersonating Trezor, the attackers delivered their message through infrastructure recipients already associated with the company while exploiting a particularly urgent fear: the exposure of a wallet recovery seed.

Another third-party compromise in weeks

Trezor said it disabled the compromised Brevo account within 20 minutes and worked to have the malicious domain taken down at the DNS level. The company has not reported any confirmed wallet theft from the campaign, and says users who only clicked without entering their wallet backup remain safe.

Advertisement

The Brevo compromise comes just weeks after a separate breach involving shipping provider ShipMonk. That incident reportedly exposed data belonging to approximately 81,000 customers across multiple cryptocurrency hardware-wallet companies, including around 14,000 Trezor customers. Leaked home addresses could increase the risk of targeted phishing, theft, or wrench attacks.

A wrench attack is a type of attack in which cybercriminals go physical, using threats or violence to force crypto holders to surrender access to their funds.

The pattern goes back to 2024, when attackers compromised another of Trezor’s third-party providers. Attackers accessed the support ticketing portal and stole data from roughly 66,000 users. BleepingComputer reported that attackers used the stolen information in phishing attempts designed to steal victims’ 24-word wallet recovery seeds.

Following the latest incident, Trezor said it was reviewing its “vendor relationships and security requirements,” putting its dependence on third-party providers under fresh scrutiny.

What Trezor users should do now

Trezor recommends that its users should:

  • Not click any link asking for a wallet backup, as the company “will never contact you asking for your wallet backup.”
  • Delete suspicious emails requesting a wallet backup. Users may also report them to Trezor through the contact options on its official website before deletion.

Trezor advises anyone who entered a wallet backup on the malicious site to immediately create a new wallet with a new recovery seed and transfer their funds to it.

However, these recommendations extend beyond crypto:

  • Don’t click security links simply because they arrive from a familiar company.
  • Verify them through the company’s official website or app.
  • Use multifactor authentication for email, exchange, and other online accounts, while remembering that MFA cannot protect a wallet once its recovery phrase has been exposed.
  • Treat recovery phrases, passwords, and other authentication secrets as information that should never be shared in response to an unsolicited request.
Advertisement

Companies also need to examine the vendors they trust. Enterprises should assess third-party security controls, limit vendor access, and prepare for incidents involving compromised communications platforms rather than treating vendor security as someone else’s problem.

Consumers should similarly consider more than a company’s own security claims. Its email, support, shipping, and customer-management providers may also hold information that attackers can exploit.

For both users and businesses, a message arriving through a legitimate channel should be treated as one trust signal — not proof that its instructions are safe.

Read more: The IDScan.net breach shows how stolen identity data can create lasting security risks after attackers gain access to sensitive customer records.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.