Trezor Customers Hit by Second Vendor Breach in Weeks as Phishing Campaign Targets 347,000 Users
The hardware wallet maker disclosed that attackers compromised its email marketing provider Brevo, enabling them to distribute hundreds of thousands of fraudulent messages designed to steal customer wallet credentials.
Trezor, a leading hardware cryptocurrency wallet manufacturer, has notified its user base of a second major security incident within recent weeks, stemming from a compromise at one of its service providers. The company revealed this week that Brevo, a marketing automation platform Trezor depends on for customer communications, fell victim to a cyberattack that gave threat actors the ability to distribute roughly 347,000 fraudulent emails impersonating the wallet maker.
The malicious messages contained a deceptive link that, once clicked, prompts users to download an application requesting their wallet recovery password. One of the phishing emails used the subject line: "Critical Security Alert: STM32 Entropy Vulnerability." Obtaining a wallet's backup password would allow criminals to permanently drain funds stored on the blockchain.
According to Brevo's incident disclosure, attackers gained entry to 138 separate Brevo customer accounts to orchestrate the mass phishing campaign. The marketing platform acknowledged that a security misconfiguration allowed the intruders' access to be "not properly scoped," explaining that "wrongly granted" permissions gave the attackers reach across all organizations connected to their compromised accounts.
This incident exemplifies a widespread vulnerability in modern business operations: when third-party vendors holding customer information become targets, the primary company's security posture becomes irrelevant. Trezor emphasized that its own infrastructure, products, and account systems remained uncompromised.
The Brevo breach marks the second significant data exposure affecting Trezor users in recent months. In August, the company disclosed that ShipMonk, a logistics partner handling hardware shipments, had suffered a data breach exposing personal information—including names, phone numbers, email addresses, and physical addresses—of at least 81,000 customers who had purchased and received Trezor hardware.
These breaches create heightened vulnerability for cryptocurrency holders and other high-net-worth individuals to targeted extortion and physical attacks. Security researchers have documented cases where criminals use stolen personal data to locate victims and employ so-called "wrench" attacks—coercive physical confrontations designed to extract passwords and access codes.
Following the ShipMonk compromise, Trezor users reported receiving fraudulent postal mail purporting to originate from the company, complete with QR codes linking to counterfeit websites designed to harvest wallet credentials. In response to the Brevo incident, Trezor announced it is reassessing its vendor relationships and cautioned users that their email addresses may become targets for additional phishing attempts in the future.


