Trezor said a data breach at Brevo, the third-party marketing platform it uses to send newsletters, is being used by criminals to target customers with phishing attacks. The hardware wallet maker said Wednesday that an unauthorized actor gained access to Brevo’s system and sent emails to 347,000 Trezor customers.
Brevo is a platform businesses use for customer communications. According to Trezor, scammers were able to send the message using Trezor’s domain name, which made the phishing email look more credible. The email included a malicious link telling users to download an app and enter their wallet backup.
In a public warning, Trezor said: “Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating…”
The disclosure comes after Trezor last month said data from 11,742 customers had been exposed after its third-party fulfillment partner, ShipMonk, was targeted. The company then said last week that an additional 67,000 U.S. customers had their names, email addresses, phone numbers, shipping addresses and order numbers leaked in that breach.
Trezor says it disabled the domain within 20 minutes
Trezor said on Wednesday: “We took down the domain at the DNS level within 20 minutes, preventing the link from working for anyone else and limiting access to 2,500 people who had clicked it before we took it down.”
The company added that those email addresses could be used in future phishing attacks. It also said no other Trezor system was touched. Trezor said it has suspended the Brevo account to stop further email distribution.
Trezor also reminded users that it never asks customers for their wallet backups.
Other wallet-related customer data incidents have surfaced this year
Trezor said criminals have been targeting customer data this year. It referenced a case in which scammers obtained customer information through Global-e, the payment processor used by crypto wallet company Ledger, and then sent phishing emails.
Last month, wallet provider SafePal also disclosed a data breach involving unauthorized access to order information for about 39,798 customers, including personal details such as names, addresses and purchase data.
The report was first published by Bitcoin Magazine and written by Mathew Di Salvo.

