Trezor Faces Phishing Threats After Brevo Email Breach Exposes User Data
Trezor is grappling with a serious security issue following a breach of its third-party email service provider, Brevo. This incident has exposed the email addresses of around 347,000 Trezor newsletter subscribers, making them vulnerable to phishing attempts.
The breach, which occurred on September 9-10, 2026, allowed hackers to exploit a vulnerability in Brevo’s single sign-on (SSO) authentication system. This flaw enabled unauthorized access to multiple customer accounts, with attackers sending phishing emails to Trezor subscribers under the guise of a 'Critical Security Alert: STM32 Entropy Vulnerability.'
Trezor has since taken down the compromised email domain and is conducting an investigation into the breach. The company emphasized that no passwords, wallet data, or other personal information were accessed during the incident. However, the exposure of email addresses poses a significant risk, as these can be reused for phishing scams.
Other crypto firms, including BitBox and CoinTracking, also reported similar phishing attempts linked to the Brevo breach. Solana Mobile has issued warnings to its users about the heightened risk of phishing emails following the incident.
This breach follows another incident involving Trezor's shipping partner, ShipMonk, which leaked customer data earlier this summer. Trezor reassured users that its devices and software have not compromised any keys or funds, stating that they maintain control over the security of their products.
In light of these events, Trezor plans to reduce the amount of customer information retained by third-party partners and will reassess its vendor relationships and security protocols.
FAQ
What happened with Trezor and Brevo?
Trezor experienced a security breach involving its third-party email service provider, Brevo, which exposed the email addresses of approximately 347,000 Trezor newsletter subscribers to potential phishing attacks.
What kind of data was exposed in the Brevo breach?
The breach exposed email addresses of Trezor newsletter subscribers, but no passwords, wallet data, or other personal information were accessed during the incident.
What steps is Trezor taking in response to the breach?
Trezor has taken down the compromised email domain, is conducting an investigation into the breach, and plans to reduce the amount of customer information retained by third-party partners.
Are Trezor devices and software affected by this breach?
No, Trezor has reassured users that its devices and software have not compromised any keys or funds, and they maintain control over the security of their products.
What should Trezor users do to protect themselves from phishing attempts?
Trezor users should be vigilant and cautious of unsolicited emails, especially those claiming to be security alerts. It's advisable to verify the source of any communication before taking action.
Comments
Comments are moderated before publish.
No comments yet — be the first.