Skip to content
Trezor Users Targeted by Phishing After Brevo Data Breach

Trezor Users Targeted by Phishing After Brevo Data Breach

First seen 11 Sep 2026, 01:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 02:17 UTC
  • 347,000 Trezor customers targeted by phishing emails due to Brevo breach.
  • Attackers exploited Trezor's domain to send convincing phishing emails.
  • Trezor disabled the compromised domain within 20 minutes, but 2,500 users clicked malicious links.

Trezor, a Bitcoin hardware wallet manufacturer, reported a data breach involving Brevo, a third-party marketing platform. This breach allowed attackers to send phishing emails to 347,000 Trezor customers, exploiting Trezor's domain to enhance the emails' credibility. The phishing emails contained malicious links aimed at tricking users into downloading harmful applications and entering their wallet backups. Trezor acted quickly, disabling the compromised domain within 20 minutes, but approximately 2,500 users had already interacted with the phishing links. Trezor has since suspended its Brevo account to prevent further email distribution. This incident follows previous breaches affecting Trezor's fulfillment partner and other cryptocurrency wallet providers earlier this year. Trezor reassured users that it never requests wallet backups via email.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-10
Trezor announces Brevo breach
Trezor reported that a breach of Brevo allowed phishing emails to be sent to 347,000 customers.
Kucoin
2026-09-10
Phishing emails sent
Phishing emails containing malicious links were sent to Trezor customers, exploiting the company's domain.
Binance
2026-09-10
Trezor disables compromised domain
Trezor disabled the compromised domain at the DNS level within 20 minutes to prevent further access to phishing links.
Kucoin
Recent
Trezor suspends Brevo account
Trezor suspended its Brevo account to halt further email distribution following the breach.
Kucoin

More articles in this cluster (2)

Following this threat?

Track Brevo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed