Trezor Users Hit by Phish via Brevo Breach

eSecurity Planet · Medium sophistication
Last updated September 15, 2026

Attackers broke into Brevo, the email platform Trezor uses for newsletters, and sent a phishing “security warning” from Trezor’s real mailing system. The email claimed a serious hardware issue could expose wallet recovery seeds and pushed people to a malicious site/app that asked for a wallet backup. The campaign reached 347,000 subscribers, and about 2,500 clicked before Trezor shut it down.

How the Attack Worked

Attackers gained access to Brevo, the third-party email platform Trezor uses to send its newsletters. Using that access, they sent a phishing email directly through Trezor's legitimate mailing system, meaning the message technically came from a real, trusted sending channel. The email warned recipients of a serious 'STM32 Entropy Bug' that could allegedly expose wallet recovery seeds, then directed them to a malicious website and application that asked for their wallet backup. The campaign reached 347,000 subscribers, and roughly 2,500 people clicked the malicious link before Trezor disabled the compromised Brevo account within about 20 minutes and worked to take the malicious domain down at the DNS level.

Why It Succeeded

The core reason this lure worked is that it arrived through a channel recipients already trusted: Trezor's own newsletter system. Most phishing awareness training focuses on spotting spoofed senders or suspicious domains, but this email didn't need to spoof anything, it was sent from the real infrastructure. Combined with a fear-based pretext about a hardware vulnerability threatening users' funds, the message created urgency that pushed people to act before verifying the claim through other means.

What to Watch For

  • Requests for a wallet backup or recovery seed, which should never be shared with anyone or entered into an external site
  • Urgent claims about device vulnerabilities that pressure immediate action
  • Links directing users away from official apps or websites to complete a 'security' step
  • Messages that arrive through a normally trusted channel but ask for unusual or sensitive information

Building Resistance

Organizations and individuals should treat messages from trusted brands as one signal of legitimacy, not proof that the instructions inside are safe. Recovery phrases, passwords, and other authentication secrets should be treated as information that is never shared in response to an unsolicited request, regardless of how official the message looks. Because this incident shows how breaching a trusted vendor can give attackers a direct route to a company's audience, IT and security teams managing SaaS or vendor access should plan for the possibility that a legitimate communication platform could be misused to reach users directly. Anyone who did submit a wallet backup on the malicious site should assume compromise and move funds to a new wallet with a new recovery seed immediately.

Key findings

  • Attackers used a breach at Brevo (Trezor’s newsletter provider) to send phishing emails through Trezor’s legitimate newsletter channel.
  • The lure claimed a serious “STM32 Entropy Bug” could expose wallet recovery seeds, creating urgency and fear.
  • Victims were driven to a malicious website/application that requested their wallet backup (recovery seed).
  • The campaign hit 347,000 subscribers; 2,500 clicked the malicious link before Trezor intervened.
  • Trezor disabled the compromised Brevo account within ~20 minutes and worked to take down the malicious domain at the DNS level.
  • Trezor stated its products, infrastructure, and users’ wallets were not compromised, and that clicking alone (without entering wallet backup) was not enough to lose funds.

Who’s being targeted

  • Commonly targeted roles: All employees (general awareness), Customer support teams, Marketing/communications teams (email platform admins), IT/Security teams managing SaaS/vendor access.
  • Affected industries: Cryptocurrency / digital assets, Consumer electronics, Email/marketing platform providers (SaaS).
  • Attack channels: email, website.
  • Impersonated: Trezor (official newsletter channel).

Red flags to watch for

  • Asks for a wallet backup/recovery seed (a secret that should never be shared)
  • Creates urgency/fear about immediate loss of funds due to a ‘serious’ bug
  • Pushes users to a website/app outside normal, trusted workflows
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers send phishing emails through Trezor's real newsletter?

Attackers compromised Trezor's account at Brevo, the third-party email platform Trezor uses for newsletters, and used that access to send a fake security alert directly through Trezor's legitimate mailing system.

What did the phishing email claim?

It claimed Trezor devices were affected by a serious 'STM32 Entropy Bug' that could expose users' wallet seeds, creating urgency for recipients to act quickly.

What should someone do if they entered their wallet backup on the malicious site?

Trezor advises anyone who entered a wallet backup on the malicious site to immediately create a new wallet with a new recovery seed and transfer their funds to it.

How many people were affected by this campaign?

The campaign reached 347,000 subscribers, and about 2,500 clicked the malicious link before Trezor shut it down.

Read the video transcript

Imagine this: a scary security alert from Trezor, sent through Trezor’s real newsletter system… and it’s the phish. Attackers broke into Brevo, Trezor’s email vendor, and blasted 347,000 users a fake ‘STM32 Entropy Bug’ warning, pushing them to a site and app that calmly asked for one thing: your wallet backup, your recovery seed. Here’s the catch: Trezor said their devices and wallets weren’t hacked, and just clicking that link didn’t steal funds. The only way this works is if you actually type your recovery seed into that website or app. So if any email ever asks for a wallet backup or recovery phrase, no matter how legit it looks, do one thing: stop, close it, and go straight to the official app or website to check there instead.

Similar attacks

Trezor Users Hit by “Critical Security Alert” Phish

Trezor Users Hit by “Critical Security Alert” Phish

Trezor reported that about 347,000 customers received phishing emails after attackers abused a breach at its third‑party email marketing provider, Brevo. The phishing message used a “Critical Security Alert” theme and linked to a malicious site that attempted to trick users into entering their…

September 11, 2026
Passkey-Themed Phishing Hits Microsoft 365

Passkey-Themed Phishing Hits Microsoft 365

Microsoft warns of an active social engineering campaign where attackers pose as an IT help desk and pressure employees to “update” passkeys/MFA/SSO. Victims are sent to fake Microsoft sign-in pages or tricked into approving access via device-code login, enabling attackers to add their own MFA…

September 14, 2026
Brevo Breach Fuels Crypto Newsletter Phishing

Brevo Breach Fuels Crypto Newsletter Phishing

Attackers abused access to Brevo (an email marketing platform) to send highly convincing phishing emails from legitimate cryptocurrency company domains to newsletter subscribers. The lures claimed urgent security issues (hardware vulnerability or data breach) and pushed victims to click links,…

September 11, 2026
Crypto Newsletter Breach Triggers Fake Security Emails

Crypto Newsletter Breach Triggers Fake Security Emails

Attackers abused access to a third-party email newsletter provider to send convincing “security alert” emails from legitimate-looking crypto company domains. The emails pushed users to click links that led to phishing sites designed to look nearly identical to real platforms. Trezor, CoinTracking,…

September 10, 2026
Brevo Breach Sparks Trezor Phishing Wave

Brevo Breach Sparks Trezor Phishing Wave

Trezor said attackers breached its third-party email provider (Brevo) and gained access to Trezor’s email domain, triggering phishing emails to subscribers. The scam emails used a fake “critical security alert” about a supposed microcontroller vulnerability and attempted to trick users into handing…

September 10, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026