The Trezor Brevo phishing attack that unfolded on 9 September 2026 reached 347,000 email addresses, with 2,500 users clicking a malicious link before Trezor pulled the domain down, the company has confirmed. What made the campaign particularly nasty is that the emails did not need to spoof anything: as BetaNews reports, the messages passed through Brevo’s own systems under Trezor’s account, so they sailed straight through the email authentication checks that normally flag a dodgy sender.
How the Trezor Brevo phishing attack was carried out
Trezor uses Brevo as its third-party marketing platform for newsletter campaigns. According to SecurityWeek, Brevo has confirmed that an attacker exploited how it handles SAML Single Sign-On (SSO) to gain access to 138 accounts. Trezor’s was among them, which gave the attacker a legitimate sending pipeline into the inboxes of everyone on Trezor’s opt-in newsletter list.
Recipients received fake ‘critical security alert’ emails sent from help@trezor.io, warning that a ‘hardware microcontroller vulnerability’ in Trezor cold storage wallets’ STM32 microcontrollers could expose their wallet seeds to brute-force cracking. The emails urged users to click a link that led to a download prompt, which then asked them to enter their wallet backup, handing their funds directly to the attacker.
Trezor says it took down the domain used in the campaign within 20 minutes, disabling the link before the majority of recipients could act on it. Even so, 2,500 users had already clicked through by that point.
‘The incident affected our opt-in newsletter database, roughly 347,000 email addresses,’ Trezor said. ‘These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched. We have suspended the Brevo account to stop further email distribution.’
Brevo’s background and the scale of the breach
Brevo is not a small outfit. The Record from Recorded Future News reports that the Paris-founded email marketing firm, which launched in 2012, raised more than $580 million in December to help expand into other parts of the customer relationship management business. The breach of 138 accounts through the SAML SSO vulnerability affected not only Trezor but other customers of the platform.
Trezor noted that the incident affected 120 Brevo accounts in its own disclosure, where an unauthorised actor gained access and used it to send emails from various customer accounts, Trezor’s included. The suspended Brevo account and the rapid domain takedown appear to have contained the immediate damage, though Trezor’s warning that the harvested 347,000 addresses could be recycled in future attacks is the more uncomfortable lingering concern.
A pattern of third-party breaches
This is not the first time Trezor has found itself cleaning up after a supplier’s security failure. In January 2024, the company disclosed a breach of its third-party support ticketing portal, where attackers stole data (including names, usernames, and email addresses) from roughly 66,000 users.
More recently, threat actors hacked ShipMonk, Trezor’s logistics and shipping provider, by exploiting a critical Metabase SQL injection zero-day vulnerability, and made off with customers’ order data: full names, shipping addresses, email addresses, and phone numbers. Trezor initially said the ShipMonk incident affected nearly 14,000 customers, but a follow-up investigation found an additional 67,000 US customers were also caught up in it, bringing the total to 81,000 individuals. Customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between 10 May and 8 August 2026 were also affected. BleepingComputer subsequently reported that ShipMonk received extortion emails from the ShinyHunters extortion gang in the wake of that breach.
For Trezor users, the immediate action is straightforward: do not enter your wallet seed phrase or backup into any application prompted by an email link, regardless of how convincing the sender address looks. Given that these messages passed authentication entirely, ‘looks legitimate’ is no longer a useful filter.

