Trezor: 347,000 users phished after Brevo email-platform breach; earlier ShipMonk breach exposed data of ~81,000 buyers
Attackers who compromised Trezor's marketing email provider Brevo via a SAML SSO flaw sent fake 'Critical Security Alert: STM32 Entropy Vulnerability' emails from [email protected] to 347,000 Trezor newsletter subscribers; 2,500 clicked before the phishing…
Trezor confirmed that attackers who compromised its marketing email provider Brevo sent phishing emails to 347,000 of its opted-in newsletter subscribers. BleepingComputer dates the Brevo incident to September 9, 2026, while Malwarebytes reports the accounts were accessed on September 10, 2026 (sources disagree). Per Brevo, the intruder created an account, enabled SAML SSO, and used its own identity provider to access 138 customer accounts (BleepingComputer reported 120 accounts affected); contacts were exfiltrated from 43 accounts, and Malwarebytes reports six accounts were used to send the phishing emails. The Trezor-themed messages, sent from [email protected] with the subject 'Critical Security Alert: STM32 Entropy Vulnerability', claimed an STM32 microcontroller vulnerability exposed wallet seeds and directed recipients to a malicious app/site asking them to enter their wallet backup. Trezor said 2,500 users clicked the link before the phishing domain was taken down within 20 minutes of detection, and its Brevo account was suspended; potential fund losses remain unknown. Customers of Swiss wallet maker BitBox and crypto tax calculator CoinTracking also received phishing emails from legitimate domains (Malwarebytes says both firms confirmed; SecurityWeek says they 'appear affected'). Trezor separately disclosed an earlier breach at logistics partner ShipMonk, exploited through a critical Metabase SQL injection zero-day, affecting roughly 81,000 customers (TechCrunch says at least 81,000) and exposing names, phone numbers, email addresses, and postal addresses; the ShinyHunters gang sent extortion emails to Trezor. Trezor stated its own products, wallets, and account systems were unaffected, warned customers to expect further phishing attempts, and noted the exported contact lists could fuel future targeted attacks; TechCrunch noted victims face crypto theft risk including physical 'wrench' attacks.
- Brevo breach timing: BleepingComputer reports the incident occurred September 9, 2026; Malwarebytes reports the 138 accounts were accessed on September 10, 2026 (sources disagree).
- Scope per Brevo: attacker created an account, enabled SAML SSO, and used its own identity provider to access 138 customer accounts; contacts exfiltrated from 43 accounts; six accounts used to send phishing emails (per Malwarebytes).…
- 347,000 Trezor opted-in newsletter subscribers received phishing emails from [email protected] with the subject line 'Critical Security Alert: STM32 Entropy Vulnerability'.
- Emails claimed an STM32 microcontroller entropy vulnerability exposed wallet seeds and linked to a malicious app/site asking users to enter their wallet backup (password).
- 2,500 users clicked the malicious link before the phishing domain was taken offline within 20 minutes of detection; Trezor's Brevo account was suspended.
- Potential fund losses remain unknown.
- BitBox (Swiss wallet maker) and CoinTracking (crypto tax calculator) customers also received phishing emails from legitimate domains.
- Exported contact lists could enable future targeted phishing campaigns; Trezor warned customers to expect further attempts.
Coverage timelineoldest first · each row is one article
- · 6d agoTrezor: 347,000 users targeted in phishing attacks after Brevo breach
BleepingComputer· 65
Trezor reported phishing after the Brevo breach targeted 347,000 newsletter subscribers, with 2,500 users clicking before the domain was taken down.
- · 6d agoTrezor Says 347,000 Users Received Phishing Emails After Brevo Hack
SecurityWeek· 65
Attackers abused Brevo's SAML SSO to access 138 accounts, sending phishing emails to 347,000 Trezor customers and exfiltrating contacts from 43 accounts.
- · 6d agoScammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
TechCrunch · Security· 62
Third-party breaches at Trezor's email and shipping vendors exposed customer data, fueling phishing campaigns targeting hundreds of thousands of crypto wallet owners.
- · 5d agoCrypto customers targeted by scammers after email marketing provider breach
Malwarebytes Labs· 75
Attackers exploited a Brevo SAML SSO flaw to access 138 accounts and phish crypto customers of Trezor, CoinTracking, and BitBox.