Trezor Customers Targeted by Phishing Scams Following Recent Data Breach
By Editor • September 11, 2026 • 1 min read
Trezor, a prominent manufacturer of hardware crypto wallets, has issued a warning to its customers regarding a significant data breach involving one of its service providers. This is the second incident of its kind in just a few months, raising alarms about the security of personal information among crypto owners.
In a recent blog post, Trezor revealed that the breach occurred at Brevo, a marketing technology firm it relies on for sending out newsletters. Hackers exploited this incident to disseminate approximately 347,000 phishing emails to Trezor customers, embedding malicious links that could compromise wallet security. One of the deceptive email subject lines included a warning about a supposed 'Critical Security Alert,' designed to lure users into revealing sensitive information.
Details of the Breach
Brevo confirmed that the attackers gained access to 138 accounts, allowing them to send a large volume of phishing emails. The company acknowledged that a flaw in their security protocols permitted the hackers to access accounts across multiple organizations improperly. This incident underscores a prevalent issue in cybersecurity where third-party vendor data is compromised, putting end-users at risk.
Previous Incidents and Ongoing Risks
This breach follows another incident in August where Trezor's shipping partner, ShipMonk, was compromised, leading to the exposure of personal information, including names and addresses, of over 81,000 customers. Trezor has cautioned that such data breaches could not only lead to financial theft but also increase risks of targeted violence and physical attacks on crypto holders.
As a precautionary measure, Trezor is reassessing its partnerships with vendors and has alerted customers that their email addresses may be exploited for future phishing attempts. The company has urged users to remain vigilant against fraudulent communications.
Source: techcrunch.com