
Phishing Attack: Scammers Target Trezor Users After Email Provider Breach
Crypto hardware wallet manufacturer Trezor is warning users for the second time in two months after a third-party vendor suffered a data breach, exposing customer contact details to online scammers.
In a public announcement, Trezor confirmed that attackers hit Brevo, a marketing technology provider that Trezor uses to deliver email newsletters. The security compromise allowed attackers to send roughly 347,000 phishing emails directly to Trezor customers. The malicious messages contained direct links disguised as official communications from Trezor support.
When recipients clicked the embedded link, the site prompted them to download a fake application that requested their wallet recovery seed phrase. Scammers used alarming subject lines like “Critical Security Alert: STM32 Entropy Vulnerability” to trick users into handing over emergency backup keys. With access to a wallet seed phrase, attackers can drain cryptocurrency funds from public blockchain networks instantly.
Brevo published an incident update admitting that attackers accessed 138 user accounts to send out mass spam campaigns. Brevo explained that a system flaw granted broad account permissions incorrectly across external client profiles, allowing attackers to reach contact databases across multiple organizations.
This security breach highlights a recurring risk across crypto hardware firms. While core wallet firmware and seed generation routines remain safe, outside sales vendors and marketing tools hold sensitive user lists. Trezor stated that its internal systems, product hardware, and software apps suffered zero direct intrusion.
However, this incident marks the second data leak involving Trezor customers over recent weeks. In August, mailing company ShipMonk suffered a data breach that exposed names, phone numbers, email addresses, and home delivery locations for over 81,000 Trezor buyers.
Exposing physical delivery addresses and contact information creates real safety risks for crypto owners. Criminals can use exposed location records to launch targeted physical threats or coercion tactics aimed at stealing private keys.
Following the ShipMonk breach, some customers received physical mail letters containing fake QR codes. Scanning those codes directed victims to fraudulent websites designed to capture wallet passwords.
Trezor confirmed it is reviewing relationships with outside vendors, urging users to remain vigilant against incoming phishing campaigns targeting their inbox.
Relying on external marketing software creates security gaps for crypto firms. Protecting digital assets requires strong operational security across every third-party service holding private customer records.







