Brevo Breach Sparks Trezor Phishing Wave

Protos · Medium sophistication
Last updated September 10, 2026

Trezor said attackers breached its third-party email provider (Brevo) and gained access to Trezor’s email domain, triggering phishing emails to subscribers. The scam emails used a fake “critical security alert” about a supposed microcontroller vulnerability and attempted to trick users into handing over their wallet backups.

Key findings

  • Trezor reported its third-party email provider Brevo was breached and that attackers accessed Trezor’s email domain.
  • Users received phishing emails with the subject “Critical Security Alert: STM32 Entropy Vulnerability.”
  • The phishing attempt tried to convince users to “give up their wallet backups.”
  • Other crypto firms using Brevo (BitBox, CoinTracking, Peach Bitcoin, Blocktrainer) warned users about phishing attempts tied to similar fake breach/vulnerability claims.

Who’s being targeted

  • Commonly targeted roles: All staff (general phishing awareness), Customer Support, Marketing/CRM teams, Security/IT incident response, Executives (brand impersonation and customer communications approval).
  • Affected industries: Cryptocurrency / digital assets, Financial services, Technology vendors serving crypto firms.
  • Attack channels: email.
  • Impersonated: Trezor (newsletter/security team), CoinTracking (security/breach notification).

Awareness takeaways

  • Treat unexpected ‘critical security’ emails as suspicious, verify via official channels before clicking anything.
  • Never share wallet backups/seed phrases; any request for them is a major red flag.
  • Third-party provider breaches can be used to make phishing emails look legitimate, so increase scrutiny after vendor incidents.

Red flags to watch for

  • Urgent ‘critical security alert’ tone pushing immediate action
  • Request to provide wallet backups/seed phrase (a high-risk request)
  • Trezor warned the message is not from them and told users not to click links
  • Breach claim may be fabricated to drive panic
  • Security messages arriving unexpectedly via email
  • Multiple firms warning about phishing related to the same email provider incident
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email from Trezor: subject line screams, “Critical Security Alert: STM32 Entropy Vulnerability.” Looks legit, right? Behind the scenes, Trezor’s email provider, Brevo, was breached. Scammers used Trezor’s real email domain to blast this fake alert and push you to “secure” your wallet by giving up your backup. Here’s the tell: no legitimate crypto service, Trezor, BitBox, CoinTracking, anyone, will ever ask for your wallet backup or seed phrase by email. The moment you see that request, it’s game over for the scammer if you stop. So if you get any “critical security alert” email, don’t click, go to the service’s website or app yourself and check there instead.

Similar attacks

Crypto Newsletter Breach Triggers Fake Security Emails

Crypto Newsletter Breach Triggers Fake Security Emails

Attackers abused access to a third-party email newsletter provider to send convincing “security alert” emails from legitimate-looking crypto company domains. The emails pushed users to click links that led to phishing sites designed to look nearly identical to real platforms. Trezor, CoinTracking,…

September 10, 2026
Fake M&A Wire Fraud and Trezor Phishing Alert

Fake M&A Wire Fraud and Trezor Phishing Alert

This bulletin describes multiple real-world scams where attackers manipulate trust to steal money or sensitive data. Notably, attackers impersonated executives to pressure legal teams into moving M&A discussions to WhatsApp/personal email to trigger international wire transfers, and Trezor users…

September 10, 2026
Trezor Users Targeted by Phishing Calls & QR Letters

Trezor Users Targeted by Phishing Calls & QR Letters

After a breach at shipping partner ShipMonk, attackers obtained Trezor customers’ contact and shipping details, increasing the risk of scams. Reports on Reddit indicate customers have already received phishing phone calls and physical letters containing QR-code phishing lures. Trezor warned…

September 8, 2026
AI-Aided Crypto Scam Used Phishing + Vishing Combo

AI-Aided Crypto Scam Used Phishing + Vishing Combo

Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those…

August 19, 2026
Fraud Ring Targets Crypto Users via Phone + Phish

Fraud Ring Targets Crypto Users via Phone + Phish

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands,…

August 18, 2026
Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026