The cryptocurrency hardware wallet maker Trezor disclosed that a phishing campaign launched earlier this week reached 347,000 email addresses, resulting in 2,500 individuals clicking on a malicious embedded link.

Following a Wednesday warning, Trezor confirmed that attackers who compromised Brevo, the company's third-party email marketing platform, leveraged the breach to target customers subscribed to its newsletter distribution list.

Victims received deceptive messages purporting to originate from help@trezor.io with subject lines warning of a "critical security alert." The emails falsely claimed that a "hardware microcontroller vulnerability" affecting the STM32 microcontrollers in Trezor's cold storage wallets could enable attackers to crack wallet seeds through brute-force methods.

The phishing scheme directed recipients to click a link leading to a fraudulent application that requested users to supply their wallet backup information.

Trezor stated that the malicious domain was disabled within 20 minutes of discovery, which constrained the total number of successful clicks to 2,500 before the link became inoperative.

On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts. An unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's

Trezor

The incident affected our opt-in newsletter database, roughly 347,000 email addresses. These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched. We have suspended the Brevo account to stop further email distribution.

Trezor

Pattern of Third-Party Breaches

Trezor phishing email
Trezor phishing email (Geo Soul)

This incident marks the latest in a series of security compromises affecting Trezor through external service providers. In January 2024, the company experienced a breach of its third-party support ticketing system, during which attackers obtained personal information including names, usernames, and email addresses from approximately 66,000 users.

Additionally, Trezor disclosed a breach last month stemming from a compromise of ShipMonk, its logistics and fulfillment partner. Threat actors exploited a critical Metabase SQL injection zero-day vulnerability to access ShipMonk's infrastructure and extract customer order information containing full names, shipping addresses, email addresses, and phone numbers.

Trezor's initial assessment indicated that 14,000 customers were impacted by the ShipMonk incident. However, a subsequent investigation expanded the scope to include an additional 67,000 U.S. customers, bringing the total affected to 81,000 individuals.

The ShipMonk breach also extended to customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who placed orders between May 10 and August 8, 2026.

Following the ShipMonk breach, the extortion group ShinyHunters sent threatening messages to ShipMonk demanding payment, according to information obtained by BleepingComputer.

Source: BleepingComputer