Trezor reported that about 347,000 customers received phishing emails after attackers abused a breach at its third‑party email marketing provider, Brevo. The phishing message used a “Critical Security Alert” theme and linked to a malicious site that attempted to trick users into entering their wallet backup, which could lead to stolen crypto funds.
Key findings
- Attackers abused Brevo account access to send phishing emails to contacts stored in compromised accounts, including Trezor’s Brevo contact list.
- Trezor said about 347,000 customer email addresses were targeted with a phishing email using a “Critical Security Alert” lure tied to an alleged hardware vulnerability.
- The phishing email included a link to a malicious website; Trezor warned that funds could be lost if victims entered their wallet backup.
- Trezor reported about 2,500 users clicked the link before the site was taken offline roughly 20 minutes after detection.
- Brevo attributed the initial access to an SSO/SAML scoping issue that allowed wider access than intended.
Who’s being targeted
- Commonly targeted roles: Customer Support, Security Awareness, Marketing/Communications, Incident Response, Customers.
- Affected industries: Cryptocurrency / digital assets, Financial services (crypto wallets and exchanges), SaaS / marketing platforms.
- Attack channels: email, website.
- Impersonated: Trezor (security alert / support).
Awareness takeaways
- Never enter or share a wallet backup/seed phrase because it can directly lead to stolen funds.
- Treat urgent “critical security alert” emails as suspicious and verify via the company’s official website/support channels before clicking anything.
- Expect phishing spikes after third‑party provider incidents; reinforce heightened scrutiny after breach notifications.
Red flags to watch for
- Creates urgency with a “Critical Security Alert” subject line
- Pushes users to click a link to a site outside normal support flows
- Asks for a wallet backup/seed phrase, which legitimate providers should never request
Read the video transcript
Imagine this hits your inbox: “Critical Security Alert: STM32 Entropy Vulnerability” from what looks like Trezor. This is how 347,000 Trezor users got phished when attackers abused Brevo’s email system to blast out a fake ‘critical hardware vulnerability’ alert. The link opened a fake site telling people to enter their wallet backup. That’s the whole heist: if you type your seed phrase there, your crypto can be emptied in minutes. Your move: if any email ever asks for a wallet backup or seed phrase, stop and go straight to the official site or app yourself, never type that phrase into a link you were sent.