Phishing Emails Target Crypto Users After Brevo Email Provider Breach

Phishing Emails Target Crypto Users After Brevo Email Provider Breach

First seen 10 Sep 2026, 19:16 UTC ProtosTherecord.Media 62.2

Article Content

Browse articles
ThreatCluster

On September 10, 2026, multiple cryptocurrency companies, including Trezor and BitBox, alerted customers about phishing emails sent after a breach of the email provider Brevo. Hackers accessed Brevo's system, allowing them to send emails that appeared legitimate, using company domains to deceive users. Trezor users received emails titled 'Critical Security Alert: STM32 Entropy Vulnerability,' while CoinTracking users were targeted with a 'Data Breach Notice.' Brevo confirmed that an attacker accessed 120 customer accounts, prompting immediate action to close the access. The phishing emails alarmed recipients, leading some to click on malicious links that directed them to fake websites. This incident follows a series of breaches affecting Trezor, including a recent leak of personal details of over 80,000 customers from its shipping partner. Both Trezor and BitBox are investigating the situation and have urged users not to engage with the phishing attempts.

Key Points: • Hackers breached Brevo, sending phishing emails to Trezor and other crypto users. • Trezor confirmed no passwords or wallet data were compromised in the breach. • This incident follows multiple breaches affecting Trezor, raising ongoing security concerns.

Ask AI about this cluster

Timeline

2026-08-01
ShipMonk breach disclosed
Trezor revealed a breach of its shipping partner ShipMonk, affecting over 80,000 customers.
Protos
2026-09-10
Brevo email provider breached
Hackers accessed Brevo, allowing phishing emails to be sent to customers of Trezor, BitBox, and others.
Therecord.Media
2026-09-10
Phishing emails reported
Trezor and CoinTracking users received phishing emails that appeared legitimate, urging immediate action.
Protos