Trezor warns customers again after data breach at email marketing provider Brevo
Hardware crypto wallet maker Trezor has disclosed that hackers who breached its email marketing provider Brevo sent roughly 347,000 phishing emails to its customers. It is the second such supply-chain incident to hit Trezor in recent months.

Hardware crypto wallet maker Trezor has told customers that one of its service providers, marketing technology company Brevo, suffered a cyberattack that exposed customer data to hackers. Trezor uses Brevo to send newsletters to its customer base.
According to Trezor, the breach allowed hackers to send around 347,000 phishing emails to its customers, with messages designed to look like they came from Trezor itself. One subject line used in the campaign read "Critical Security Alert: STM32 Entropy Vulnerability."
Malicious app requests wallet password
Clicking the link in the phishing emails triggers a download of an app that asks victims to enter their wallet backup password. If a hacker obtains that password, they can irreversibly drain the victim's funds from the public blockchain.
Brevo said in an incident update that hackers gained access to 138 of its accounts to distribute the phishing messages at scale. The company said the intrusion stemmed from a flaw that failed to properly scope account access, wrongly granting the attackers reach into every organization those accounts were connected to.
Trezor said none of its own products, wallets, or account systems were compromised in the incident.
Second breach in recent months
This marks the second breach affecting Trezor in a short period. In August, the company warned customers that shipping partner ShipMonk had been breached, exposing the names, phone numbers, email addresses, and postal addresses of at least 81,000 people who had purchased Trezor hardware.
Such breaches can put crypto holders and other wealthy individuals at risk of targeted physical attacks, including so-called "wrench attacks," in which criminals use physical coercion to extract passwords. Following the ShipMonk breach, some customers reported receiving fraudulent letters by mail containing a QR code that leads to a fake page designed to steal wallet passwords.
Trezor said it is reevaluating its relationships with vendors and cautioned that customer email addresses could be targeted again in future phishing attempts.


