Trezor says 347,000 users received phishing emails after Brevo breach; BitBox and CoinTracking also hit
An attacker who compromised email-marketing provider Brevo by abusing SAML SSO scoping sent fake security-alert phishing emails from legitimate domains to roughly 347,000 Trezor newsletter subscribers, with 2,500 clicking before the phishing domain was taken…
Threat actors compromised email-marketing provider Brevo, which crypto firms Trezor, BitBox, and CoinTracking share (CoinTracking identified the provider as Brevo). Brevo said the intruder created an account, enabled SAML SSO, and used its own identity provider with improperly scoped access rights to reach 138 customer accounts, exporting contact lists from 43 of them; Malwarebytes reported six accounts were used to send the phishing emails. SecurityWeek, BleepingComputer, TechCrunch, and Malwarebytes put the figure at 138 accounts, while The Record reported Brevo saying 120 — the sources disagree on this number. Reports also disagree on the incident date: BleepingComputer says September 9, 2026, while Malwarebytes says September 10. The phishing emails were sent from legitimate company domains (e.g., [email protected]) with fake alerts such as 'Critical Security Alert: STM32 Entropy Vulnerability' and 'Data Breach Notice: Please refresh API Keys'; the Trezor-themed email cited a fabricated STM32 microcontroller entropy flaw supposedly exposing wallet seeds to brute-force attacks and linked to a malicious app asking users to enter their wallet backup. Trezor said roughly 347,000 opted-in newsletter subscribers received the emails and that 2,500 users clicked the link before Trezor disabled the phishing domain within 20 minutes of detection; the Brevo account was suspended. Potential fund losses are unknown. Trezor stated its own products, wallets, and account systems were unaffected and warned customers to expect further phishing attempts, a risk amplified by the exported contact lists. Separately, and not part of this incident, Trezor disclosed a prior breach at logistics provider ShipMonk — exploited via a critical Metabase SQL injection zero-day — that exposed names, phone numbers, email addresses, and postal addresses of 81,000 customers (revised up from about 14,000, including 67,000 additional US customers) who ordered between May 10 and August 8, 2026, and drew extortion emails from the ShinyHunters gang. The Record also cited CertiK figures that physical 'wrench' attacks on crypto holders rose 33 percent year-over-year with $124 million in losses in 2026.
- Attacker abused Brevo's SAML SSO scoping — creating an account, enabling SAML SSO, and using its own identity provider — to access 138 Brevo customer accounts (SecurityWeek, BleepingComputer, TechCrunch, Malwarebytes); The Record reported…
- Six Brevo accounts were used to send phishing emails; contacts were exported from 43 accounts, enabling future targeted phishing
- Incident date disputed: BleepingComputer says September 9, 2026; Malwarebytes says September 10, 2026
- Roughly 347,000 Trezor opted-in newsletter subscribers received phishing emails; 2,500 users clicked the malicious link
- Phishing domain was taken down within 20 minutes of detection; the Brevo account was suspended; potential fund losses unknown
- Fake emails came from legitimate domains (e.g., [email protected]) with subjects like 'Critical Security Alert: STM32 Entropy Vulnerability' and 'Data Breach Notice: Please refresh API Keys', luring victims to enter wallet backups via a…
- BitBox and CoinTracking also confirmed customers received phishing emails from their legitimate domains
- Trezor said its own products, wallets, and account systems were unaffected and warned customers to expect further phishing attempts
Coverage timelineoldest first · each row is one article
- · 5d agoMultiple crypto companies warn customers of phishing emails after alleged provider breach
The Record· 55
Attackers compromised 120 Brevo email accounts and sent convincing phishing emails to Trezor, BitBox, and CoinTracking newsletter subscribers.
- · 5d agoTrezor warns users of email provider breach, phishing attacks
BleepingComputer· 58
Trezor says attackers breached its third-party email provider and are phishing customers with fake STM32 entropy vulnerability alerts.
- · 4d agoTrezor: 347,000 users targeted in phishing attacks after Brevo breach
BleepingComputer· 65
Trezor reported phishing after the Brevo breach targeted 347,000 newsletter subscribers, with 2,500 users clicking before the domain was taken down.
- · 4d agoTrezor Says 347,000 Users Received Phishing Emails After Brevo Hack
SecurityWeek· 65
Attackers abused Brevo's SAML SSO to access 138 accounts, sending phishing emails to 347,000 Trezor customers and exfiltrating contacts from 43 accounts.
- · 4d agoScammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
TechCrunch · Security· 62
Third-party breaches at Trezor's email and shipping vendors exposed customer data, fueling phishing campaigns targeting hundreds of thousands of crypto wallet owners.
- · 4d agoCrypto customers targeted by scammers after email marketing provider breach
Malwarebytes Labs· 75
Attackers exploited a Brevo SAML SSO flaw to access 138 accounts and phish crypto customers of Trezor, CoinTracking, and BitBox.