Live Cybersecurity News Ticker | Codekeeper

Trezor Users Hit by Phishing After Brevo Platform Hack

Written by Content Team | Sep 14, 2026, 5:42:19 AM

A phishing campaign reached roughly 347,000 Trezor customers after an attacker got into Brevo, the marketing platform Trezor uses for newsletters. Brevo says the attacker reached 138 accounts, sent phishing from six, and exported contacts from 43, with BitBox and CoinTracking users apparently hit as well.

The attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into that configuration, then signed in as them through their own identity provider. That access was never scoped to one organization, so it reached every organization those users could see. Brevo closed the route two hours after spotting it, signed out every user, and disabled the links.

Because the emails left real Brevo infrastructure, they passed the usual authentication checks. Trezor's carried the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and pointed at a site set up to harvest wallet backups. Around 2,500 people clicked in the 20 minutes before Trezor caught it.

It is Trezor's second third-party failure in a month, after a breach at shipping provider ShipMonk exposed nearly 14,000 people, plus another 67,000 US customers disclosed on September 4.

Source: SecurityWeek