Kucoin Trezor Users Targeted by Phishing After Brevo Data Breach
Article Content
- •347,000 Trezor customers targeted by phishing emails due to Brevo breach.
- •Attackers exploited Trezor's domain to send convincing phishing emails.
- •Trezor disabled the compromised domain within 20 minutes, but 2,500 users clicked malicious links.
Trezor, a Bitcoin hardware wallet manufacturer, reported a data breach involving Brevo, a third-party marketing platform. This breach allowed attackers to send phishing emails to 347,000 Trezor customers, exploiting Trezor's domain to enhance the emails' credibility. The phishing emails contained malicious links aimed at tricking users into downloading harmful applications and entering their wallet backups. Trezor acted quickly, disabling the compromised domain within 20 minutes, but approximately 2,500 users had already interacted with the phishing links. Trezor has since suspended its Brevo account to prevent further email distribution. This incident follows previous breaches affecting Trezor's fulfillment partner and other cryptocurrency wallet providers earlier this year. Trezor reassured users that it never requests wallet backups via email.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Brevo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…