NewsTradingSentimentCalendarCommunityBriefing
Tech

Trezor breach exposes 347,000 users to phishing risks

By Tech Desk · 2026-09-11 · 3 min read
A digital padlock with a keyhole
Illustration: Tradingbird

A security lapse at an email provider has left hundreds of thousands of Trezor customers vulnerable to targeted scams, with thousands already falling for fake alerts.

Trezor, a major manufacturer of hardware wallets for cryptocurrency, has confirmed that a breach at its third-party email provider, Brevo, has exposed the contact details of 347,000 subscribers. This incident is not a direct hack of Trezor's own servers, but rather a failure at a vendor that handles marketing communications. The exposure means that attackers now have a verified list of people who own digital asset storage devices, making them high-value targets for future social engineering attempts.

The immediate consequence of this data leak was a wave of phishing attacks that reached thousands of inboxes earlier this week. According to reports from BleepingComputer, 2,500 users clicked on malicious links embedded in these fraudulent emails. The attackers disguised their messages as urgent security notices, exploiting the fear of losing one's digital wealth to trick recipients into compromising their devices.

Fake alerts exploit user fear

The phishing emails impersonated Trezor’s official support team, claiming that a critical vulnerability in the hardware microchips of their wallets could allow brute-force attacks on seed phrases. These seed phrases are the only way to recover funds if a device is lost or damaged, making them the most sensitive piece of information in the cryptocurrency world. By presenting a plausible technical threat, the attackers aimed to bypass the skepticism that users might otherwise apply to unsolicited emails.

The emails instructed recipients to download a specific application to patch the alleged flaw. Once installed, this software likely sought to steal the user's seed phrase or grant remote access to the device. Trezor states that it acted quickly to mitigate the damage, taking down the malicious domain used in the attacks within 20 minutes of detection. This rapid response limited the total number of compromised users to 2,500, but it highlights how quickly automated phishing campaigns can spread once a valid email list is stolen.

Vendor breaches create systemic risk

The root cause of the exposure was a security incident at Brevo, which affected 120 customer accounts on September 9, 2026. The unauthorized actor gained access to the platform and used it to send emails from various customer inboxes, including Trezor’s. Trezor has since suspended its Brevo account to prevent further distribution of emails, but the damage to the data set is done. The company emphasized that no other internal Trezor systems were touched, isolating the breach to the marketing database.

This incident underscores a persistent trade-off in modern digital security: reliance on third-party services for essential functions like communication creates a chain of custody that is only as strong as its weakest link. For users, the stake is high because the exposed data is not just names and addresses, but the identifier of people who hold significant financial assets. The catch is that even if Trezor secures its own perimeter, it cannot control the security practices of its vendors, leaving its customers exposed to risks outside its direct operational control.

Pattern of repeated security lapses

This is not the first time Trezor has faced a data exposure linked to a third party. In January 2024, a breach of its support ticketing portal led to the theft of personal data from 66,000 users. More recently, last month, a vulnerability in ShipMonk, its logistics provider, resulted in the exposure of order data, including names, addresses, and phone numbers, for over 81,000 customers. These recurring incidents suggest a systemic issue with how security is managed across the extended supply chain of digital asset companies.

BleepingComputer also reported that the logistics provider, ShipMonk, subsequently received extortion emails from the ShinyHunters gang following the breach. This pattern of vendor breaches followed by extortion attempts indicates that attackers are increasingly targeting the periphery of major organizations. For users, the takeaway is that receiving a phishing email is no longer a sign of poor personal security, but a potential side effect of a company’s broader supply chain vulnerabilities. The risk remains elevated for all 347,000 affected users, as their email addresses are now known to be valid and associated with high-value hardware wallets.

Based on reporting by BleepingComputer, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories