Trezor: 347,000 users phished after Brevo email provider breach; ShipMonk breach impact rises to 81,000 customers
Attackers who breached Trezor's email marketing provider Brevo sent fake 'STM32 Entropy Vulnerability' phishing emails to 347,000 newsletter subscribers; 2,500 clicked before the domain was taken down within 20 minutes. Trezor also raised the impact of a…
Trezor warned customers that attackers breached Brevo, its third-party email marketing provider, and sent fake emails from [email protected] with the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' to 347,000 opted-in newsletter subscribers. The emails claimed an STM32 microcontroller flaw exposed wallet seeds to brute-force attacks and linked to a malicious app asking users to enter their wallet backup. Trezor said 2,500 users clicked the link before the phishing domain was disabled within 20 minutes; potential fund losses are unknown. Brevo said the intruder created an account, enabled SAML SSO, and used its own identity provider to access 138 customer accounts and exfiltrate contacts from 43 of them (one report put affected accounts at 120 and others at 138; sources disagree, and one dates the account access to September 10, 2026 while the incident is dated September 9, 2026 elsewhere). Six accounts were used to send the phishing emails, and exported contact lists could fuel future targeted phishing. Crypto firms BitBox and CoinTracking also confirmed customers received phishing emails from legitimate domains. Separately, Trezor disclosed that a prior breach at logistics partner ShipMonk, exploited via a critical Metabase SQL injection zero-day, exposed names, phone numbers, email addresses, and postal addresses of roughly 81,000 customers who received orders between May 10 and August 8, 2026 — revised upward from about 14,000, including 67,000 additional US customers. The ShinyHunters gang sent extortion emails after the ShipMonk breach. Trezor stated its own products, wallets, and account systems were unaffected and warned customers to expect further phishing attempts, with victims facing crypto theft risk including physical 'wrench' attacks.
- Fake emails from [email protected] with subject 'Critical Security Alert: STM32 Entropy Vulnerability' were sent to 347,000 opted-in Trezor newsletter subscribers
- The emails claimed an STM32 microcontroller entropy flaw exposed wallet seeds to brute-force attacks and asked users to enter their wallet backup via a malicious link/app
- 2,500 users clicked the phishing link; the malicious domain was taken down within 20 minutes of detection
- Brevo said the attacker created an account, enabled SAML SSO, and used its own identity provider to access 138 customer accounts; one report says 120 accounts were affected (sources disagree)
- Contacts were exfiltrated from 43 Brevo accounts; six accounts were used to send the phishing emails (per Malwarebytes Labs)
- Brevo incident is dated September 9, 2026 by BleepingComputer; Malwarebytes says the 138 accounts were accessed on September 10 (dates differ across reports)
- BitBox and CoinTracking customers also received phishing emails sent from legitimate domains
- Prior ShipMonk breach exploited a critical Metabase SQL injection zero-day to steal customer data
Coverage timelineoldest first · each row is one article
- · 7d agoTrezor warns users of email provider breach, phishing attacks
BleepingComputer· 58
Trezor says attackers breached its third-party email provider and are phishing customers with fake STM32 entropy vulnerability alerts.