Trezor Phishing Campaign Hits 347,000 Emails After Brevo Account Breach
Trezor discloses that a phishing campaign targeting its customers this week reaches 347,000 email addresses after attackers breach Brevo, the third-party email marketing platform the company uses for newsletters. The attackers send fake "critical security alert" emails from a spoofed Trezor address, claiming that a vulnerability in the STM32 microcontrollers of Trezor hardware wallets could expose wallet seeds to brute-force attacks.
The malicious emails urge recipients to click a link that prompts them to download an app asking for their wallet backup. Trezor says it takes down the phishing domain within 20 minutes, limiting the impact to 2,500 customers who click the link before it is disabled. The company suspends its Brevo account to stop further email distribution and warns that the exposed addresses could be used in future phishing attempts. No other Trezor systems are affected.
This is the third recent security incident involving Trezor's third-party providers, following a January 2024 breach of its support ticketing portal that exposes data on roughly 66,000 users, and a breach of logistics partner ShipMonk last month that affects 81,000 customers in total. The repeated incidents highlight the ongoing risk that compromised vendors pose to crypto hardware wallet users, who remain prime targets for phishing attacks aimed at stealing wallet seeds.