Trezor says a phishing campaign targeted about 347,000 customer email addresses after hackers breached its third-party marketing provider, Brevo. Around 2,500 recipients clicked the malicious link before the company disabled it.
The attackers sent fake security warnings from a legitimate Trezor email address. They claimed that a hardware flaw threatened the recovery seeds used to protect customers’ cryptocurrency wallets.
However, the warning was false. Its purpose was to convince recipients to download a malicious application and enter their wallet backup details.
Hackers Sent Emails Through Brevo
Brevo suffered a security incident on September 9, 2026. According to Trezor, an unauthorized actor accessed the marketing platform and used several customer accounts to send phishing emails.
The breach affected 120 Brevo accounts, including the one used for Trezor’s newsletter campaigns. As a result, the attackers could send messages from an authentic company email address.
The Trezor phishing attack targeted people who had opted in to receive newsletters. The exposed database contained approximately 347,000 email addresses.
Trezor suspended its Brevo account after discovering the campaign. This action stopped the platform from sending further malicious emails on its behalf.
Fake Alert Claimed Wallets Had a Security Flaw
The phishing emails appeared as critical security alerts. They warned recipients about an alleged vulnerability in the microcontrollers used by Trezor hardware wallets.
According to the false message, attackers could exploit the supposed flaw to brute-force wallet recovery seeds. The email then urged users to follow an embedded link.
That link directed victims to a malicious domain and prompted them to download an application. The fraudulent software asked users to enter their wallet backup.
A wallet recovery seed can provide complete access to the cryptocurrency stored in a wallet. Therefore, anyone who entered this information may face a serious risk of asset theft.
Trezor hardware wallets themselves were not compromised. Moreover, the attackers did not access the company’s internal systems through this incident.
Trezor Disabled Link Within 20 Minutes
Trezor says it took down the malicious domain within 20 minutes. Disabling the site prevented the link from reaching more victims.
However, approximately 2,500 customers had already clicked it. The company did not say how many of those users downloaded the application or entered their recovery seed.
The phishing campaign may create further risks beyond the original message. Since attackers obtained the newsletter email database, they could reuse those addresses in future scams.
Customers may receive convincing follow-up emails that reference Trezor or cryptocurrency security. Consequently, users should treat unexpected wallet warnings with caution.
Trezor advises customers never to enter a recovery seed into an app, website or online form. The company will not request this information through email.
No Other Trezor Systems Were Affected
Trezor says the incident remained limited to its Brevo newsletter account. No other company system was accessed.
The breach did not expose wallet balances, recovery seeds or other information stored on Trezor devices. Instead, it gave the attackers access to email addresses used for marketing communications.
Still, sending messages from a legitimate company account makes phishing attempts more credible. Normal authentication checks may also allow such emails to bypass some spam filters.
The Trezor phishing attack shows how criminals can exploit a trusted third-party provider to reach customers. Even when the main company remains secure, a compromised supplier can create an effective route for fraud.
Previous Breaches Affected Trezor Customers
This is not the first incident involving one of Trezor’s external service providers. In January 2024, attackers breached a third-party support portal used by the company.
That incident exposed names, usernames and email addresses linked to about 66,000 customers.
Trezor disclosed another breach in August 2026 after hackers compromised logistics provider ShipMonk. The attackers exploited a critical Metabase SQL injection vulnerability and stole customer order information.
The exposed records included names, shipping addresses, email addresses and phone numbers. Trezor initially reported that nearly 14,000 customers were affected.
However, a later investigation identified another 67,000 victims in the United States. This finding increased the total to 81,000 people.
Customers in Brazil, Colombia, Italy, Portugal, Sweden and the United Kingdom were also affected. The exposed international records related to orders delivered between May 10 and August 8, 2026.
ShipMonk later received extortion emails linked to the ShinyHunters group.
Users Should Protect Their Recovery Seeds
Anyone who entered a wallet seed after clicking the malicious link should move their assets to a newly created wallet immediately. They should perform this process through trusted software obtained from official sources.
Users who only clicked the link should remain alert for unusual activity. They should also remove any application downloaded through the phishing page.
In addition, recipients should expect further targeted messages because the attackers may retain the exposed email addresses.
The strongest protection is to keep recovery seeds offline and private. A legitimate wallet provider will never need customers to submit this information through an emailed link.


0 responses to “Trezor Says 347,000 Users Targeted After Brevo Breach”