Skip to content
Trezor Marketing Platform Compromised; 347000 Users Targeted by Phishing Emails

Trezor Marketing Platform Compromised; 347000 Users Targeted by Phishing Emails

Kucoin September 10, 2026

ChainCatcher report: Trezor, a manufacturer of Bitcoin hardware wallets, warned that a data breach occurred on Brevo, a third-party marketing platform used to send newsletters, enabling attackers to send phishing emails to 347,000 Trezor customers. The attackers exploited Trezor’s domain to send emails, making the phishing attempts more convincing; the emails contained malicious links designed to trick users into downloading applications and entering their wallet backups. Trezor stated that it disabled the compromised domain at the DNS level within 20 minutes, preventing further access to the links, but approximately 2,500 users had already clicked on them. Trezor has suspended its Brevo account to halt further email distribution and emphasized that no other Trezor systems were affected. The company also reminded users that Trezor never requests customers to provide their wallet backups. Prior to this incident, Trezor disclosed last month that its third-party fulfillment partner, ShipMonk, was compromised, resulting in the exposure of data for 11,742 customers; last week, it further revealed that the personal information—including names, email addresses, phone numbers, shipping addresses, and order numbers—of an additional 67,000 U.S. customers was exposed. Earlier this year, payment processor Global-e for the cryptocurrency wallet Ledger and wallet provider SafePal also suffered data breaches, with SafePal reporting unauthorized access to order information of approximately 39,800 customers.

Extracted Entities

Attack Types (1)

Platforms (1)