Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor customers were targeted in a phishing campaign after a breach of Brevo, Trezor's third-party email marketing provider. Approximately 347,000 email addresses were exposed, and 2,500 users clicked on malicious links in phishing emails that impersonated Trezor and claimed a hardware vulnerability. The phishing emails attempted to trick users into downloading an app to steal wallet backup seeds. Trezor quickly took down the malicious domain within 20 minutes, limiting the impact. The breach only affected the newsletter database, and no other Trezor systems were compromised. This incident follows previous breaches involving Trezor's support and logistics providers.
AI Analysis
Technical Summary
On September 9, 2026, Brevo, a third-party email marketing platform used by Trezor, suffered a security breach affecting 120 Brevo accounts, including Trezor's. Threat actors used this access to send phishing emails to approximately 347,000 Trezor newsletter subscribers. The phishing emails falsely warned of a hardware microcontroller vulnerability in Trezor wallets and included malicious links prompting users to download an app to capture wallet backup seeds. About 2,500 users clicked the malicious links before Trezor took down the phishing domain within 20 minutes. Trezor suspended its Brevo account to prevent further email distribution. No other Trezor systems were compromised. This incident follows earlier breaches involving Trezor's support ticketing portal and logistics provider, ShipMonk.
Potential Impact
The breach exposed the email addresses of approximately 347,000 Trezor newsletter subscribers, enabling targeted phishing attacks. About 2,500 users clicked on malicious links, potentially exposing their wallet backup seeds to theft. However, Trezor's core systems were not compromised, and the phishing domain was taken down quickly, limiting further impact. The exposed email addresses may be used in future phishing attempts. Previous breaches have also exposed customer personal data, increasing overall risk to Trezor users.
Mitigation Recommendations
Trezor has suspended its Brevo account to stop further phishing email distribution and took down the malicious phishing domain within 20 minutes of detection. Users are advised to remain vigilant against phishing attempts and avoid clicking suspicious links or downloading unverified apps. Since no Trezor systems were compromised, no direct action on Trezor wallets is required beyond standard phishing awareness. Monitor official Trezor communications for updates.
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Description
Trezor customers were targeted in a phishing campaign after a breach of Brevo, Trezor's third-party email marketing provider. Approximately 347,000 email addresses were exposed, and 2,500 users clicked on malicious links in phishing emails that impersonated Trezor and claimed a hardware vulnerability. The phishing emails attempted to trick users into downloading an app to steal wallet backup seeds. Trezor quickly took down the malicious domain within 20 minutes, limiting the impact. The breach only affected the newsletter database, and no other Trezor systems were compromised. This incident follows previous breaches involving Trezor's support and logistics providers.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On September 9, 2026, Brevo, a third-party email marketing platform used by Trezor, suffered a security breach affecting 120 Brevo accounts, including Trezor's. Threat actors used this access to send phishing emails to approximately 347,000 Trezor newsletter subscribers. The phishing emails falsely warned of a hardware microcontroller vulnerability in Trezor wallets and included malicious links prompting users to download an app to capture wallet backup seeds. About 2,500 users clicked the malicious links before Trezor took down the phishing domain within 20 minutes. Trezor suspended its Brevo account to prevent further email distribution. No other Trezor systems were compromised. This incident follows earlier breaches involving Trezor's support ticketing portal and logistics provider, ShipMonk.
Potential Impact
The breach exposed the email addresses of approximately 347,000 Trezor newsletter subscribers, enabling targeted phishing attacks. About 2,500 users clicked on malicious links, potentially exposing their wallet backup seeds to theft. However, Trezor's core systems were not compromised, and the phishing domain was taken down quickly, limiting further impact. The exposed email addresses may be used in future phishing attempts. Previous breaches have also exposed customer personal data, increasing overall risk to Trezor users.
Defensive Guidance
Trezor has suspended its Brevo account to stop further phishing email distribution and took down the malicious phishing domain within 20 minutes of detection. Users are advised to remain vigilant against phishing attempts and avoid clicking suspicious links or downloading unverified apps. Since no Trezor systems were compromised, no direct action on Trezor wallets is required beyond standard phishing awareness. Monitor official Trezor communications for updates.
Technical Details
- Classification
- {"confidence":0.8,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/","fetched":true,"fetchedAt":"2026-09-11T08:01:58.346Z","wordCount":691}
Threat ID: 6aa3b57691cc7f3848dee0b6
Added to database: 09/11/2026, 08:01:58 UTC
Last enriched: 09/11/2026, 08:02:09 UTC
Last updated: 09/11/2026, 15:14:29 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.