Trezor Brevo Breach Triggers 347,000 Crypto Phishing Emails
Trezor warns 347,000 phishing emails followed a Brevo breach, weeks after ShipMonk exposed personal data belonging to at least 81,000 hardware wallet buyers.
Summary
On September 11, 2026, Trezor warned that attackers exploited newsletter provider Brevo to send about 347,000 phishing emails, its second vendor related breach warning in two months. Hackers accessed 138 Brevo accounts after a permissions flaw granted overly broad access across reachable organizations. Messages included the subject “Critical Security Alert: STM32 Entropy Vulnerability” and linked to an app requesting wallet backup passwords, which can enable irreversible theft on the public blockchain. Trezor said its products, wallets and account system were unaffected.
In August, a breach at shipping partner ShipMonk exposed names, phone numbers, email addresses and postal addresses of at least 81,000 people who bought and received Trezor hardware. Some later received fake Trezor letters containing QR codes linked to password theft pages. The exposed data could facilitate more phishing, targeted violence and physical “wrench” attacks against crypto owners and other wealthy individuals. Trezor is reevaluating vendor relationships and warns that compromised email addresses may be targeted again.
Positives
- All Trezor products, wallets and account systems remained unaffected by the Brevo incident.
- Brevo traced the campaign to 138 accessed accounts and identified improperly scoped permissions as the enabling flaw.
- Trezor alerted customers after both the August ShipMonk breach and September Brevo phishing campaign.
- Trezor is reevaluating vendor relationships after two supplier compromises in as many months.
Risks & concerns
- About 347,000 phishing emails directed Trezor customers to an app designed to steal wallet backup passwords.
- A stolen backup password can enable irreversible theft of cryptocurrency recorded on the public blockchain.
- Brevo’s permissions flaw granted attackers broad access across organizations reachable from 138 compromised accounts.
- ShipMonk exposed names, phone numbers, emails and postal addresses belonging to at least 81,000 Trezor hardware buyers.
- Leaked contact and address data could support future phishing, fraudulent letters, targeted violence and physical wrench attacks.