Crypto News

Trezor users hit by phishing emails after marketing platform breach

Trezor users hit by phishing emails after marketing platform breach

Trezor users hit by phishing emails after marketing platform breach

Trezor announced that a breach of its third‑party marketing service allowed scammers to send phishing emails to 347,000 of its customers. The emails used the Trezor domain and contained a link that asked users to download an app and enter their wallet backup.

Key facts

  • Breach involved the email platform Brevo, which was accessed by an unauthorized actor.
  • Phishing email titled “Critical Security Alert: STM32 Entropy Vulnerability” was not sent by Trezor.
  • Trezor took down the malicious domain at the DNS level within 20 minutes, limiting exposure to about 2,500 users who clicked the link before it was disabled.
  • No other Trezor systems were compromised.
  • The Brevo account has been suspended to stop further emails.

Trezor's response

The company posted a warning on Twitter on September 9, 2026, urging users not to click any links in the email. It also reminded customers that it never asks for wallet backup information.

Earlier data leaks

In August 2026, Trezor disclosed that a breach of its fulfillment partner ShipMonk exposed data of 11,742 customers. A subsequent report added that 67,000 U.S. customers had their names, email addresses, phone numbers, shipping addresses and order numbers leaked.

Confirmed details

  • The phishing campaign targeted 347,000 Trezor customers.
  • The malicious domain was disabled within 20 minutes, affecting roughly 2,500 users.
  • Only the email service was compromised; Trezor’s core wallet infrastructure remained untouched.

Open questions

It is not yet known how the attackers obtained access to Brevo’s system or whether additional users may be targeted in future phishing attempts.

Why it matters

Hardware wallets like Trezor store private keys that control crypto assets. Phishing emails that ask for wallet backups can lead to loss of funds if users share their backup information.

Sources

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!