Trezor says breach at email marketing provider led to phishing emails sent to 347,000 customers

Trezor says breach at email marketing provider led to phishing emails sent to 347,000 customers

N
News Editor
2026-09-10 21:28:55
Trezor said a breach at Brevo, the third-party marketing platform it uses for newsletters, allowed an unauthorized actor to send phishing emails to 347,000 customers using Trezor’s domain. The message, titled “Critical Security Alert: STM32 Entropy Vulnerability,” urged recipients to download an app and enter their wallet backup. Trezor said it took the domain down at the DNS level within 20 minutes, which limited exposure to 2,500 people who clicked the link before it was disabled. The company added that no other Trezor system was affected and that it has suspended its Brevo account to halt further distribution. The disclosure follows other recent incidents tied to Trezor’s third-party partners. Last month, the company said data from 11,742 customers was exposed after fulfillment partner ShipMonk was targeted. Last week, it said another 67,000 U.S. customers had names, email addresses, phone numbers, shipping addresses and order numbers leaked. Trezor also pointed to similar cases this year involving Ledger’s payment processor Global-e and a SafePal breach affecting about 39,798 customers’ order information.

Trezor said a data breach at Brevo, the third-party marketing platform it uses to send newsletters, is being used by criminals to target customers with phishing attacks. The hardware wallet maker said Wednesday that an unauthorized actor gained access to Brevo’s system and sent emails to 347,000 Trezor customers.

Brevo is a platform businesses use for customer communications. According to Trezor, scammers were able to send the message using Trezor’s domain name, which made the phishing email look more credible. The email included a malicious link telling users to download an app and enter their wallet backup.

In a public warning, Trezor said: “Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link. We have taken down the domain, and we are investigating…”

The disclosure comes after Trezor last month said data from 11,742 customers had been exposed after its third-party fulfillment partner, ShipMonk, was targeted. The company then said last week that an additional 67,000 U.S. customers had their names, email addresses, phone numbers, shipping addresses and order numbers leaked in that breach.

Trezor says it disabled the domain within 20 minutes

Trezor said on Wednesday: “We took down the domain at the DNS level within 20 minutes, preventing the link from working for anyone else and limiting access to 2,500 people who had clicked it before we took it down.”

The company added that those email addresses could be used in future phishing attacks. It also said no other Trezor system was touched. Trezor said it has suspended the Brevo account to stop further email distribution.

Trezor also reminded users that it never asks customers for their wallet backups.

Other wallet-related customer data incidents have surfaced this year

Trezor said criminals have been targeting customer data this year. It referenced a case in which scammers obtained customer information through Global-e, the payment processor used by crypto wallet company Ledger, and then sent phishing emails.

Last month, wallet provider SafePal also disclosed a data breach involving unauthorized access to order information for about 39,798 customers, including personal details such as names, addresses and purchase data.

The report was first published by Bitcoin Magazine and written by Mathew Di Salvo.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.