347,000 Phishing Emails Sent via Trezor Breach

Trezor confirms a data breach at email provider Brevo led to the dispatch of 347,000 malicious messages to customers.
Trezor confirmed that hackers accessed the email systems of its vendor Brevo. This breach enabled the transmission of approximately 347,000 phishing emails to Trezor customers. The messages contained a malicious link disguised as a security alert. Recipients were prompted to download an application that requested wallet backup passwords.
Compromise of the backup password allows for irreversible theft of digital assets. Trezor stated that its core wallet hardware and account infrastructure remained secure. The incident marks the second major security event affecting the company within two months. GN markets/crypto (en-US) reports that this follows a previous breach at a logistics partner.
Third-party vendor compromise details
Brevo disclosed that attackers gained access to 138 internal accounts. The company attributed the issue to a flaw in access scoping. This error granted unauthorized users broad permissions across multiple organizations. The breach exploited a third-party dependency rather than Trezor’s direct systems.
Previous incident at shipping partner
In August, Trezor reported a data leak involving its shipping partner ShipMonk. This incident exposed personal data for at least 81,000 customers. The leaked records included names, phone numbers, and postal addresses. Victims subsequently received physical mail containing QR codes leading to phishing pages.
Physical security risks for owners
The combination of digital and physical data leaks increases vulnerability. Attackers can use stolen addresses to coordinate targeted physical threats. These include coercion tactics known as wrench attacks. Trezor is currently reevaluating its vendor relationships to mitigate future risks.






