Skip to content
Trezor Warns Users of Phishing Risks Following Email Service Breach

Trezor Warns Users of Phishing Risks Following Email Service Breach

Kucoin • September 11, 2026

Trezor has recently issued another security alert to its users. The company stated that its email service provider, Brevo, was hacked, resulting in the exposure of some customer data, which attackers then used to send large-scale phishing emails. Trezor emphasized that its products, wallets, and account systems were not affected by this incident.

The Brevo account was used to send bulk phishing emails.

Brevo stated in its incident report that hackers accessed 138 Brevo accounts and used them to send a large volume of phishing messages. The company said the issue was related to a permissions control flaw, which allowed attackers to gain access beyond their intended scope and improperly reach all organizations accessible by those accounts.

For cryptocurrency users, the risk of such incidents extends beyond email compromise. If victims enter their wallet password or recovery information on a fake page, their on-chain assets may be swiftly transferred and are typically unrecoverable.

Second time in two months affecting Trezor users

This is the second data security incident affecting Trezor users in nearly two months. In August this year, Trezor alerted customers that a data breach at its logistics partner, ShipMonk, compromised the information of at least 81,000 users who had purchased and received products.

The data exposed at the time included names, phone numbers, email addresses, and mailing addresses. When combined, such information can increase the success rate of targeted scams and make it easier for attackers to impersonate official customer service, logistics providers, or after-sales channels.

Risk of offline letters and violent threats is increasing

In the weeks following the ShipMonk incident, some users have received paper letters impersonating Trezor. The letters include a QR code that, when scanned, redirects to a fraudulent page designed to trick users into entering their wallet passwords, thereby stealing their crypto assets.

Foreign media have pointed out that such leaks could also expose cryptocurrency asset holders to more severe personal risks, including "wrench attacks" that involve threatening or using direct violence to force victims to hand over their passwords. Trezor stated that it is reassessing its relationships with suppliers and warned users that the associated email addresses may still be used again for phishing attacks in the future.