Trezor has issued a warning indicating that a security compromise at the external marketing service it relies on for newsletter distribution is resulting in fraudsters aiming phishing scams at its users.
The prominent hardware wallet maker announced on Wednesday that an unauthorized intruder breached Brevo’s infrastructure and dispatched messages to 347,000 Trezor clients. Brevo is a service companies utilize for consumer outreach.
The fraudsters successfully leveraged Trezor’s official domain to transmit the message, lending significantly more credibility to the phishing scheme. The communication included a fraudulent hyperlink directing individuals to download an application and input their wallet seed phrase.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating…
— Trezor (@Trezor) September 9, 2026
This development follows Trezor’s disclosure last month revealing that records concerning 11,742 buyers were compromised after an attack on its third-party logistics vendor, ShipMonk.
Subsequently, the company stated last week that an extra 67,000 domestic customers suffered leaks involving their names, email addresses, phone numbers, postal addresses, and transaction IDs.
“We took down the domain at the DNS level within 20 minutes, preventing the link from working for anyone else and limiting access to 2,500 people who had clicked it before we took it down,” Trezor explained on Wednesday.
“These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched,” Trezor added.
“We have suspended the Brevo account to stop further email distribution.”
Trezor reiterated to consumers that it will never request individuals to provide their wallet backup phrases.
Malicious actors have heavily focused on user databases throughout the year, with fraudsters previously exploiting payment handler Global-e—associated with crypto wallet Ledger—to launch targeted phishing campaigns.
Furthermore, digital asset storage provider SafePal disclosed a security incident last month involving unauthorized exposure of roughly 39,798 buyers’ purchase records, which encompassed confidential details like full names, residential locations, and buying history.
Originally published at https://bitcoinmagazine.com/news/trezor-reveals-another-data-breach.