Trezor Users Hit by “Critical Security Alert” Phish

Security Week Feed · Medium sophistication
Last updated September 11, 2026

Trezor reported that about 347,000 customers received phishing emails after attackers abused a breach at its third‑party email marketing provider, Brevo. The phishing message used a “Critical Security Alert” theme and linked to a malicious site that attempted to trick users into entering their wallet backup, which could lead to stolen crypto funds.

Key findings

  • Attackers abused Brevo account access to send phishing emails to contacts stored in compromised accounts, including Trezor’s Brevo contact list.
  • Trezor said about 347,000 customer email addresses were targeted with a phishing email using a “Critical Security Alert” lure tied to an alleged hardware vulnerability.
  • The phishing email included a link to a malicious website; Trezor warned that funds could be lost if victims entered their wallet backup.
  • Trezor reported about 2,500 users clicked the link before the site was taken offline roughly 20 minutes after detection.
  • Brevo attributed the initial access to an SSO/SAML scoping issue that allowed wider access than intended.

Who’s being targeted

  • Commonly targeted roles: Customer Support, Security Awareness, Marketing/Communications, Incident Response, Customers.
  • Affected industries: Cryptocurrency / digital assets, Financial services (crypto wallets and exchanges), SaaS / marketing platforms.
  • Attack channels: email, website.
  • Impersonated: Trezor (security alert / support).

Awareness takeaways

  • Never enter or share a wallet backup/seed phrase because it can directly lead to stolen funds.
  • Treat urgent “critical security alert” emails as suspicious and verify via the company’s official website/support channels before clicking anything.
  • Expect phishing spikes after third‑party provider incidents; reinforce heightened scrutiny after breach notifications.

Red flags to watch for

  • Creates urgency with a “Critical Security Alert” subject line
  • Pushes users to click a link to a site outside normal support flows
  • Asks for a wallet backup/seed phrase, which legitimate providers should never request
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this hits your inbox: “Critical Security Alert: STM32 Entropy Vulnerability” from what looks like Trezor. This is how 347,000 Trezor users got phished when attackers abused Brevo’s email system to blast out a fake ‘critical hardware vulnerability’ alert. The link opened a fake site telling people to enter their wallet backup. That’s the whole heist: if you type your seed phrase there, your crypto can be emptied in minutes. Your move: if any email ever asks for a wallet backup or seed phrase, stop and go straight to the official site or app yourself, never type that phrase into a link you were sent.

Similar attacks

Brevo Breach Fuels Crypto Newsletter Phishing

Brevo Breach Fuels Crypto Newsletter Phishing

Attackers abused access to Brevo (an email marketing platform) to send highly convincing phishing emails from legitimate cryptocurrency company domains to newsletter subscribers. The lures claimed urgent security issues (hardware vulnerability or data breach) and pushed victims to click links,…

September 11, 2026
Crypto Newsletter Breach Triggers Fake Security Emails

Crypto Newsletter Breach Triggers Fake Security Emails

Attackers abused access to a third-party email newsletter provider to send convincing “security alert” emails from legitimate-looking crypto company domains. The emails pushed users to click links that led to phishing sites designed to look nearly identical to real platforms. Trezor, CoinTracking,…

September 10, 2026
Brevo Breach Sparks Trezor Phishing Wave

Brevo Breach Sparks Trezor Phishing Wave

Trezor said attackers breached its third-party email provider (Brevo) and gained access to Trezor’s email domain, triggering phishing emails to subscribers. The scam emails used a fake “critical security alert” about a supposed microcontroller vulnerability and attempted to trick users into handing…

September 10, 2026
Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
Fake M&A Wire Fraud and Trezor Phishing Alert

Fake M&A Wire Fraud and Trezor Phishing Alert

This bulletin describes multiple real-world scams where attackers manipulate trust to steal money or sensitive data. Notably, attackers impersonated executives to pressure legal teams into moving M&A discussions to WhatsApp/personal email to trigger international wire transfers, and Trezor users…

September 10, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026