ZeroHour
BleepingComputerpublished ()ingested Sergiu Gatlan
Part of a story covered by 6 sources: “Trezor says 347,000 users received phishing emails after Brevo breach; BitBox and CoinTracking also hit” — merged summary and timeline →

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

mediumPhishing & fraud exploited in the wildimportance 65
AI summary · glm-5.3-flash

Trezor reported phishing after the Brevo breach targeted 347,000 newsletter subscribers, with 2,500 users clicking before the domain was taken down.

Threat actors who breached Trezor's third-party email provider Brevo on September 9, 2026 sent fake 'critical security alert' emails from [email protected] to 347,000 opted-in newsletter subscribers, claiming an STM32 microcontroller vulnerability exposed wallet seeds. The emails linked to a malicious app that asked users to enter their wallet backup; 2,500 users clicked before Trezor disabled the phishing domain within 20 minutes. Trezor also disclosed that a prior breach via logistics provider ShipMonk, exploited through a critical Metabase SQL injection zero-day, affected 81,000 customers and drew extortion emails from the ShinyHunters gang.

  • Brevo incident on September 9, 2026 affected 120 Brevo accounts
  • 347,000 Trezor newsletter addresses targeted; 2,500 clicked the phishing link
  • Fake emails claimed a hardware microcontroller vulnerability in STM32-based wallets
  • Phishing domain taken down within 20 minutes; Brevo account suspended
  • Prior ShipMonk breach via Metabase SQL injection zero-day affected 81,000 customers; ShinyHunters sent extortion emails
Full article437 words · extracted from bleepingcomputer.com · click to collapse

Trezor

Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link.

As Trezor warned on Wednesday, threat actors who breached Brevo, its third-party email provider, were emailing customers who opted in to receive newsletters.

According to customers targeted in this phishing campaign, they received fake "critical security alert" emails from [email protected] claiming that a "hardware microcontroller vulnerability" in Trezor cold storage wallets' STM32 microcontrollers could expose their seeds to brute-force cracking.

The phishing emails tried to trick recipients into clicking a malicious link that prompted them to download an app that asked them to enter their wallet backup.

Trezor says that it took down the domain used in the phishing attacks within 20 minutes, disabling the link and limiting the campaign's impact to 2,500 customers who had clicked it before it was taken down.

"On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts. An unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's," the company said.

"The incident affected our opt-in newsletter database, roughly 347,000 email addresses. These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched. We have suspended the Brevo account to stop further email distribution."

In January 2024, Trezor disclosed another data breach after its third-party support ticketing portal was hacked and attackers stole data (including names, usernames, and email addresses) from roughly 66,000 users.

Trezor also disclosed a data breach last month after threat actors hacked ShipMonk, its logistics and shipping provider, using a critical Metabase SQL injection zero-day vulnerability, and stole customers' order data, including full names, shipping addresses, email addresses, and phone numbers.

While Trezor initially said the incident affected nearly 14,000 customers, a follow-up investigation found that the resulting breach affected an additional 67,000 U.S. customers, bringing the total to 81,000 individuals.

The company said that the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.

Since then, BleepingComputer also learned that ShipMonk received extortion emails from the ShinyHunters extortion gang following the breach.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/