Phishing waves hit Trezor customers after vendor breaches at ShipMonk and Brevo
Two separate third-party breaches — shipping partner ShipMonk (via a Metabase SQL-injection zero-day, ~81,000 customers after upward revision) and email provider Brevo (SAML SSO abuse, phishing sent to 347,000 subscribers) — are fueling phishing calls,…
Trezor maker SatoshiLabs is dealing with phishing fallout from two distinct vendor breaches. First, shipping partner ShipMonk was compromised after attackers exploited a zero-day SQL injection in Metabase's Cloud SaaS platform; the breach exposed names, emails, phone numbers, and shipping addresses. Help Net Security reported an initial figure of 3,889 affected customers plus roughly 67,000 additional US customers, while BleepingComputer put the initial figure at about 14,000 before the total was revised to 81,000 customers across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. The affected-order windows conflict between reports: Help Net Security cites orders from November 2019 to August 2021, while BleepingComputer cites May 10 to August 8, 2026. ShipMonk reportedly retained data beyond the required 90-day deletion period, and the ShinyHunters gang sent extortion emails after the breach; customers are now reporting phishing calls and QR-code phishing letters. Second, on September 9, 2026 Trezor's marketing email provider Brevo was breached. Per SecurityWeek and TechCrunch, the attacker created an account, enabled SAML SSO using its own identity provider, and accessed 138 Brevo accounts (BleepingComputer reported 120), exfiltrating contacts from 43 of them. The attackers sent roughly 347,000 fake 'Critical Security Alert: STM32 Entropy Vulnerability' emails from [email protected], claiming wallet seeds were exposed to brute-force attacks and directing recipients to a malicious app that asked for their wallet backup; 2,500 users clicked before the phishing domain was taken down 20 minutes after detection. Potential fund losses are unknown. Swiss wallet maker BitBox and crypto tax tool CoinTracking also appear affected by the Brevo compromise. Trezor states its own products, wallets, and account systems were unaffected and warns customers to expect further phishing attempts. Chainalysis estimates violent crypto attacks extracted over $30M from holders in 2026; Trezor plans anonymous delivery options and advises customers to use decoy wallets and P.O. boxes.
- ShipMonk breach exploited a zero-day SQL injection in Metabase's Cloud SaaS platform; ShipMonk retained data past the required 90-day deletion period.
- ShipMonk impact revised upward to 81,000 total customers, including 67,000 additional US customers; earlier figures were 3,889 (Help Net Security) or ~14,000 (BleepingComputer).
- Sources disagree on the affected-order window: November 2019–August 2021 (Help Net Security) vs May 10–August 8, 2026 (BleepingComputer).
- Affected ShipMonk shipments went to the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal; exposed data included names, emails, phone numbers, and postal addresses.
- ShinyHunters sent extortion emails to ShipMonk after the breach.
- Brevo breach occurred September 9, 2026; attacker created an account, enabled SAML SSO with its own identity provider, and accessed 138 Brevo accounts (BleepingComputer reported 120), exfiltrating contacts from 43.
- Roughly 347,000 Trezor newsletter subscribers received fake 'STM32 Entropy Vulnerability' emails from [email protected] linking to a malicious app that requested wallet backups; 2,500 users clicked before the domain was taken down 20 minutes…
- Potential fund losses from the Brevo phishing campaign are unknown.
Coverage timelineoldest first · each row is one article
- · 8d agoTrezor customers hit with phishing calls and letters after shipping-partner breach
Help Net Security· 50
A breach at shipping partner ShipMonk exposed data for about 67,000 additional US Trezor customers, who now face phishing calls and QR scam letters.