Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Recorded: Sept. 11, 2026, 8:10 a.m.
| Original | Summarized |
Trezor: 347,000 users targeted in phishing attacks after Brevo breach News Featured AdaptHealth confirms 4.1 million people exposed in July cyberattack Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Over 36,000 exposed Plex servers vulnerable to recent flaws New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Trezor: 347,000 users targeted in phishing attacks after Brevo breach Conti ransomware gang member sentenced to 4 years in prison New Android malware encrypts files, steals data, and harasses victims September Windows Server updates break Remote Desktop Services Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityTrezor: 347,000 users targeted in phishing attacks after Brevo breach Trezor: 347,000 users targeted in phishing attacks after Brevo breach By Sergiu Gatlan September 11, 2026 Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. Trezor phishing email (Geo Soul) Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Breach Sergiu Gatlan Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days September Windows Server updates break Remote Desktop Services New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Sponsor Posts EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance. Overdue a password health-check? Audit your Active Directory for free Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
Trezor disclosed that phishing attacks targeting its customers occurred after threat actors successfully breached Brevo, Trezor's third-party email provider. These attacks initially targeted 347,000 email addresses, and 2,500 users clicked on embedded malicious links. The fraudulent emails posed a specific threat, claiming a vulnerability in the hardware microcontroller of Trezor cold storage wallets, specifically the STM32 microcontrollers, could expose wallet seeds to brute-force cracking. These phishing attempts were designed to trick recipients into downloading an application that solicited their wallet backup information. Trezor managed to mitigate the immediate impact by disabling the malicious domain within twenty minutes, thereby limiting the campaign's fallout to the 2,500 customers who had interacted with the malicious link. The vulnerability stemmed from a prior security incident affecting Brevo itself, where an unauthorized actor gained access to the platform and utilized it to send emails originating from various customer accounts, including Trezor's, impacting the opt-in newsletter database of approximately 347,000 email addresses. This incident highlights the risks associated with relying on third-party services for sensitive customer communication. Furthermore, the text contextualizes this event by referencing previous security incidents involving Trezor, demonstrating a pattern of exposure. In January 2024, Trezor experienced a data breach stemming from a hack of its third-party support ticketing portal, which resulted in the theft of data, including names, usernames, and email addresses, from roughly 66,000 users. More recently, the company addressed a breach involving ShipMonk, its logistics and shipping provider, where threat actors exploited a Metabase SQL injection zero-day vulnerability to steal order data, including personal identifiers and shipping details, affecting 81,000 U.S. customers and customers across several other international locations. These events underscore the necessity for comprehensive security planning, particularly regarding the security posture of interdependent systems and external service providers. |