Trezor Customers Hit by Phishing Attacks Following Third-Party Breach
Hardware wallet provider **Trezor** has disclosed a recent phishing campaign that targeted 347,000 customer email addresses, with 2,500 users reportedly clicking malicious links. The attacks stemmed from a security incident at **Brevo**, Trezor's third-party email marketing provider, highlighting the persistent risks associated with supply chain vulnerabilities.
Hardware wallet manufacturer **Trezor** recently revealed details about a significant phishing campaign affecting its customer base. The attacks, which leveraged a breach at their third-party email provider, **Brevo**, targeted a substantial number of users with deceptive security alerts.
### The Phishing Campaign Unpacked
On September 9, 2026, an unauthorized actor gained access to **Brevo**'s systems, impacting 120 client accounts, including **Trezor**'s. This breach allowed the threat actor to send phishing emails from *[email protected]* to approximately 347,000 email addresses from **Trezor**'s opt-in newsletter database.
The malicious emails purported to be a "critical security alert," warning of a "hardware microcontroller vulnerability" in **Trezor** cold storage wallets' **STM32** microcontrollers. The fraudulent message claimed this vulnerability could expose users' seeds to brute-force cracking, urging recipients to download a fake application and enter their wallet backup.
**Trezor** acted swiftly, taking down the malicious domain within 20 minutes of detection. This rapid response limited the immediate impact, with the company confirming that approximately 2,500 customers clicked the embedded malicious link before it was disabled.
### A Pattern of Third-Party Vulnerabilities
This incident is not an isolated event for **Trezor**, underscoring a recurring theme of supply chain vulnerabilities impacting customer data. In January 2024, **Trezor** disclosed a data breach involving its third-party support ticketing portal, which exposed personal data of roughly 66,000 users, including names, usernames, and email addresses.
More recently, **Trezor** announced another data breach stemming from a hack at **ShipMonk**, its logistics and shipping provider. This breach, exploited through a critical **Metabase SQL injection zero-day vulnerability**, initially affected nearly 14,000 customers. A subsequent investigation revealed the true scope was much larger, impacting an additional 67,000 U.S. customers, bringing the total to 81,000 individuals. This incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who placed orders between May 10 and August 8, 2026. The **ShinyHunters** extortion gang later claimed responsibility for this breach, sending extortion emails to **ShipMonk**.
### Implications for Users and the Industry
These repeated incidents highlight the critical importance of robust third-party vendor security assessments and continuous monitoring. For **Trezor** users, the advice remains consistent: exercise extreme caution with unsolicited emails, verify the authenticity of any security alerts directly through official channels, and never enter sensitive information like wallet seeds into applications downloaded from unverified sources. The ongoing challenges faced by **Trezor** serve as a stark reminder for the broader cybersecurity community about the interconnected nature of digital security and the cascading effects of supply chain compromises.