Phishing wave hits crypto users after email provider breach

Thousands of crypto wallets faced phishing attempts after a breach at email provider Brevo. The attack exploited 120 compromised accounts to send malicious messages.
Thousands of cryptocurrency holders received phishing emails on Wednesday. The messages originated from a breach at email provider Brevo. Trezor, CoinTracking, and BitBox confirmed their customer bases were targeted. The attackers used legitimate company domains to send the alerts.
Brevo stated an attacker accessed 120 customer accounts. The company closed the access point on Thursday. It promised a full post mortem later. The firm raised over $580 million in December to expand its operations.
Attackers targeted multiple crypto firms
Trezor received emails titled Critical Security Alert. The messages urged users to click links to fix alleged issues. BitBox noted that multiple firms share the same newsletter provider. CoinTracking reported emails asking users to refresh API keys.
Users reported the emails looked highly legitimate. Several clicked links before landing on fake sites. Trezor stated it did not send the messages. The company took down the malicious domain.
Security risks remain elevated
Trezor recently suffered a breach exposing 81,000 customer details. That incident involved its shipping and logistics provider. Customers also reported receiving malicious QR codes by post. Prosecutors note criminals use stolen lists to rank targets.
Wrench attacks on crypto owners increased 33 percent year over year. Losses reached $124 million so far this year. This compares to $10.5 million in the first half of 2025. Recent incidents include the death of an investor in Paraguay.
Companies advise users to act
BitBox sent a warning to all subscribers. The firm reported the phishing domains to authorities. Most malicious links have been taken down. Trezor advised users not to click any links. GN markets/crypto (en-US) reported these developments.






