LmCast :: Stay tuned in

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Recorded: Sept. 11, 2026, 8:10 a.m.

Original Summarized

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Conti ransomware gang member sentenced to 4 years in prison

New Android malware encrypts files, steals data, and harasses victims

September Windows Server updates break Remote Desktop Services

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityTrezor: 347,000 users targeted in phishing attacks after Brevo breach

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

By Sergiu Gatlan

September 11, 2026
03:55 AM
0

Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link.
As Trezor warned on Wednesday, threat actors who breached Brevo, its third-party email provider, were emailing customers who opted in to receive newsletters.
According to customers targeted in this phishing campaign, they received fake "critical security alert" emails from help@trezor.io claiming that a "hardware microcontroller vulnerability" in Trezor cold storage wallets' STM32 microcontrollers could expose their seeds to brute-force cracking.
The phishing emails tried to trick recipients into clicking a malicious link that prompted them to download an app that asked them to enter their wallet backup.
Trezor says that it took down the domain used in the phishing attacks within 20 minutes, disabling the link and limiting the campaign's impact to 2,500 customers who had clicked it before it was taken down.
"On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts. An unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's," the company said.
"The incident affected our opt-in newsletter database, roughly 347,000 email addresses. These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched. We have suspended the Brevo account to stop further email distribution."

Trezor phishing email (Geo Soul)
In January 2024, Trezor disclosed another data breach after its third-party support ticketing portal was hacked and attackers stole data (including names, usernames, and email addresses) from roughly 66,000 users.
Trezor also disclosed a data breach last month after threat actors hacked ShipMonk, its logistics and shipping provider, using a critical Metabase SQL injection zero-day vulnerability, and stole customers' order data, including full names, shipping addresses, email addresses, and phone numbers.
While Trezor initially said the incident affected nearly 14,000 customers, a follow-up investigation found that the resulting breach affected an additional 67,000 U.S. customers, bringing the total to 81,000 individuals.
The company said that the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
Since then, BleepingComputer also learned that ShipMonk received extortion emails from the ShinyHunters extortion gang following the breach.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Trezor warns users of email provider breach, phishing attacksThe Top 4 Threats We Found by Investigating Every Alert for a QuarterMan gets six years for hacking 750 women's Snapchat accountsShinyHunters extortion gang claims Odido breach affecting millionsBigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Breach
Brevo
Phishing
Trezor

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

September Windows Server updates break Remote Desktop Services

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

Overdue a password health-check? Audit your Active Directory for free

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Trezor disclosed that phishing attacks targeting its customers occurred after threat actors successfully breached Brevo, Trezor's third-party email provider. These attacks initially targeted 347,000 email addresses, and 2,500 users clicked on embedded malicious links. The fraudulent emails posed a specific threat, claiming a vulnerability in the hardware microcontroller of Trezor cold storage wallets, specifically the STM32 microcontrollers, could expose wallet seeds to brute-force cracking. These phishing attempts were designed to trick recipients into downloading an application that solicited their wallet backup information. Trezor managed to mitigate the immediate impact by disabling the malicious domain within twenty minutes, thereby limiting the campaign's fallout to the 2,500 customers who had interacted with the malicious link.

The vulnerability stemmed from a prior security incident affecting Brevo itself, where an unauthorized actor gained access to the platform and utilized it to send emails originating from various customer accounts, including Trezor's, impacting the opt-in newsletter database of approximately 347,000 email addresses. This incident highlights the risks associated with relying on third-party services for sensitive customer communication. Furthermore, the text contextualizes this event by referencing previous security incidents involving Trezor, demonstrating a pattern of exposure. In January 2024, Trezor experienced a data breach stemming from a hack of its third-party support ticketing portal, which resulted in the theft of data, including names, usernames, and email addresses, from roughly 66,000 users. More recently, the company addressed a breach involving ShipMonk, its logistics and shipping provider, where threat actors exploited a Metabase SQL injection zero-day vulnerability to steal order data, including personal identifiers and shipping details, affecting 81,000 U.S. customers and customers across several other international locations. These events underscore the necessity for comprehensive security planning, particularly regarding the security posture of interdependent systems and external service providers.