Trezor warns of phishing after Brevo breach

Hackers used access to Trezor’s Brevo account to send about 347,000 phishing emails, adding to concerns after a recent ShipMonk data leak.
Hardware crypto wallet maker Trezor is again warning customers after a breach at one of its outside service providers exposed them to a large phishing campaign. The company said attackers used access to Brevo, a marketing tech firm it uses for newsletters, to send malicious emails that appeared to come from Trezor. Trezor’s own wallets and account systems were not breached, but customers were still put at risk through a third party. For crypto owners, a convincing fake email can be enough to start a chain of events that ends with stolen funds.
Brevo breach led to 347,000 phishing emails
In a blog post this week, Trezor said the attack on Brevo let hackers send around 347,000 phishing emails to its customers. The messages included a malicious link that downloaded an app asking the victim for their wallet backup password.
One of the subject lines used in the campaign was “Critical Security Alert: STM32 Entropy Vulnerability,” Trezor said. The phrasing was meant to look urgent and technical, making the message appear more credible.
The risk is simple but severe. If an attacker gets a wallet backup password, they can irreversibly take a person’s funds on the public blockchain. That makes the campaign especially dangerous for people who keep crypto assets in self-custody wallets and depend on backup credentials to regain access.
Brevo says access was wrongly granted
Brevo described the incident in an incident status post, saying hackers were able to access 138 Brevo accounts and use them to send the phishing emails. The company said the attackers exploited a flaw that meant their access was “not properly scoped.”
Brevo also said access had been “wrongly granted” to all organizations the hackers’ accounts could reach. As IT-PUB News notes, that suggests the issue was not confined to a single account but stemmed from a broader permissions problem inside the service.
Trezor said the Brevo breach did not affect its products, wallets, or account system. Even so, the company is now dealing with the fallout from a third-party compromise: customers may receive emails that look legitimate but are designed to steal sensitive information.
A second Trezor-linked breach in recent weeks
This is the second time in as many months that Trezor has had to alert customers about a breach at a company it relies on. In August, the company said one of its shipping partners, ShipMonk, had been compromised.
That earlier incident exposed the names, phone numbers, email addresses, and postal addresses of at least 81,000 people who bought and received Trezor wallet hardware. The latest case is different in method, but it adds to the same concern. Outside vendors can become a weak point even when the main company’s own systems are not breached.
Trezor said it was reevaluating its relationships with vendors. It also warned customers that their email addresses may be used again in future phishing attacks.
The risk goes beyond unwanted email
The consequences go beyond spam. Trezor said the data breach could put crypto owners and other wealthy individuals at risk of targeted violence and so-called “wrench” attacks, which use physical force to extract passwords from victims.
The source text also points to a pattern of abuse after the ShipMonk breach. In the weeks that followed, some people received letters by mail claiming to be from Trezor. Those letters included a QR code that opened a fake page designed to steal the victim’s crypto wallet password.
Taken together, the incidents show how leaked contact details can be reused across different scams, from email phishing to physical mail fraud. Trezor’s latest warning is not about a flaw in its hardware wallets, but it still leaves users carrying part of the security burden as they watch for the next phishing attempt.