Trezor Email Breach Exposes 347K Users to Crypto Phishing Scam
Trezor's email provider Brevo was breached, exposing 347,000 users to phishing emails.
Why it matters: Third-party breaches like this increase data exposure risks, urging crypto legal teams to strengthen incident response and consumer safeguards.
- On Sept 9, 2026, Brevo, Trezor’s email vendor, was breached affecting 120 accounts, including Trezor's official newsletter.
- Approximately 347,000 Trezor newsletter subscribers received phishing emails with malicious links targeting wallet backups.
- Trezor disabled the phishing domain within 20 minutes, limiting exposure to about 2,500 users who clicked links before takedown.
- In August 2026, ShipMonk, Trezor’s shipping partner, suffered a separate breach exposing order data of 13,689 customers internationally.
Trezor confirmed on September 9, 2026, that its email service provider Brevo (formerly Sendinblue) suffered a security breach compromising 120 accounts, including Trezor’s official newsletter account. This breach allowed attackers to send phishing emails to approximately 347,000 subscribers.
The phishing emails titled "Critical Security Alert: STM32 Entropy Vulnerability" contained malicious links prompting recipients to download an app designed to steal cryptocurrency wallet backups. Trezor warned users via Twitter and their website not to interact with the emails or links to avoid fund loss.
Upon discovery, Trezor immediately suspended its Brevo account and worked with domain registrars to take down the phishing domain at the DNS level within 20 minutes. This rapid response limited exposure to about 2,500 users who had clicked the malicious links before takedown.
In a related incident the prior month, Trezor’s shipping partner ShipMonk disclosed a data breach affecting 13,689 customers globally across the U.S., U.K., Sweden, Colombia, Brazil, Italy, and Portugal. The breach exposed order information but did not compromise Trezor’s hardware or internal IT infrastructure. ShipMonk’s official statement detailed the scope and remediation plans.
These events underscore the cybersecurity risks posed by third-party vendors in the cryptocurrency supply chain. For legal and compliance professionals, reassessing vendor risk management and breach response protocols is critical to reducing liability and protecting user trust in an evolving regulatory landscape.
By the numbers:
- 347,000 — Trezor newsletter subscribers targeted in phishing emails
- 120 — Accounts compromised in the Brevo email provider breach
- 13,689 — Customers impacted by ShipMonk data breach across multiple countries
Yes, but: Trezor’s quick detection and response minimized direct user harm, and no core wallet hardware or internal systems were compromised in either breach.
What's next: Trezor plans to conduct a thorough forensic investigation and enhance third-party vendor oversight to prevent future incidents.