The latest Trezor data breach has exposed hundreds of thousands of cryptocurrency owners to another wave of targeted phishing. Attackers abused Trezor’s email provider to distribute approximately 347,000 malicious messages through infrastructure normally trusted by customers.
The incident becomes more serious because it follows another third-party breach affecting Trezor customers only weeks earlier. That earlier compromise exposed personal information capable of making future scams considerably more believable and potentially more dangerous.
Trezor confirmed that its marketing provider Brevo suffered a security incident involving accounts used by several customers. Attackers then accessed Trezor’s newsletter environment and distributed a fake warning designed to steal cryptocurrency wallet backups.
The fraudulent email carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and presented an urgent hardware warning. Recipients clicking the included link were directed toward malicious software asking them to enter their wallet backup.
That backup can provide complete control over cryptocurrency stored inside a wallet when entered into malicious software. Unlike traditional financial fraud, stolen crypto transactions can generally become extremely difficult to reverse after funds leave the wallet.
Trezor said approximately 2,500 recipients clicked the malicious link before the associated domain was disabled twenty minutes later. The company has not confirmed how many people entered wallet backups or whether cryptocurrency was ultimately stolen.
Customers who only clicked the link remain safe provided they never entered their wallet backup online, according to Trezor. Anyone who submitted that information has been advised to transfer funds immediately into a newly created secure wallet.
The Trezor data breach did not involve the company’s hardware wallets, account infrastructure, or internal product systems. Instead, the attackers exploited access through Brevo, which Trezor used to manage and distribute its newsletter communications.
Brevo’s investigation found that attackers exploited a weakness involving the company’s implementation of SAML Single Sign-On. The flaw eventually provided unauthorized access to 138 customer accounts across the marketing platform.
The attackers first created their own Brevo account and enabled SSO before inviting legitimate users into that configuration. They then used an identity provider under their control to authenticate as users connected with those organizations.
Brevo said the critical problem appeared when those authentication privileges extended beyond the organization owning the SSO configuration. That mistake allowed attackers to reach additional organizations accessible to the affected users rather than remaining properly isolated.
Six compromised Brevo accounts were ultimately used to send phishing messages directly to their stored contact lists. Attackers also exported contacts from 43 accounts, while 93 accounts showed no meaningful malicious activity afterward.
Brevo closed the access route on September 10 and signed every active platform user out immediately afterward. The company is deploying a permanent fix designed to restrict SSO authentication exclusively to its intended organization.
What makes the Trezor data breach particularly concerning is how authentic the fraudulent emails could appear. Brevo acknowledged that messages passed ordinary authentication checks because attackers were sending them through legitimate marketing infrastructure.
That eliminates one familiar defense people often use when deciding whether an unexpected security email deserves their trust. A correctly authenticated sender becomes much less reassuring when criminals already control the authorized communication platform.
Trezor says Brevo only stored newsletter email addresses and did not possess wallet backups, passwords, or other wallet information. However, Trezor is treating all 347,000 addresses as potentially known to attackers and reusable for future phishing.
The risk becomes more complicated because some Trezor customers have already been affected by another recent vendor compromise. Shipping and fulfillment provider ShipMonk disclosed unauthorized access to customer order information during an August security incident.
Trezor initially identified nearly 14,000 customers whose information was exposed through the shipping provider’s compromised systems. A later investigation revealed older information belonging to approximately 67,000 additional United States customers remained stored unexpectedly.
Trezor now says 80,689 customers were affected by the ShipMonk incident across both initial and later findings. The exposed records included combinations of names, telephone numbers, email addresses, shipping addresses, cities, and order information.
Those details create security concerns that extend beyond another suspicious message arriving inside an email inbox. Trezor warned that stolen information could support fraudulent calls, physical letters, impersonation attempts, and potential physical security threats.
A shipping address connected with a cryptocurrency hardware-wallet customer carries particular sensitivity because it can identify where someone lives. Attackers may also infer that the person holds cryptocurrency, although the exposed ShipMonk records did not reveal wallet balances.
The separate incidents can become more dangerous when criminals combine information obtained from different sources around the same victim. An email containing accurate names, addresses, telephone numbers, and purchasing context can appear far more convincing than generic phishing.
That possibility changes how customers should interpret future communications following the Trezor data breach and ShipMonk incident. Attackers no longer need obviously fake messages when previously exposed information can help create highly personalized social-engineering campaigns.
Trezor has already warned customers that information from the shipping breach could support fake phone calls and fraudulent letters. The company specifically advises users never to enter their wallet backup online or share it with another person.
The company is also reviewing its vendor relationships and security requirements following the latest incident involving Brevo. Trezor says large companies depend on specialist providers for email delivery, global shipping, unsubscribe management, and other necessary operations.
Those relationships create an unavoidable security challenge because customer information must sometimes leave a company’s direct infrastructure. Every outside provider holding that information effectively becomes another point where attackers can search for a weaker defensive boundary.
For cryptocurrency businesses, those weaknesses can carry unusually high consequences because attackers know successful victims may control valuable digital assets. Customer databases can therefore become targeting lists even when they contain no private keys, passwords, or cryptocurrency balances.
The latest Trezor data breach demonstrates that an attacker does not need to penetrate a hardware wallet directly. Compromising a communications provider can create trusted phishing channels capable of persuading victims to surrender the secret protecting their assets.
ShipMonk demonstrates the other side of that risk because logistics providers require enough information to deliver physical products successfully. Names, telephone numbers, addresses, and purchase records can become powerful intelligence when exposed to financially motivated attackers.
Trezor says its devices remained secure throughout both incidents, which is an important distinction for customers assessing immediate risk. The security failures occurred among external service providers rather than through vulnerabilities inside Trezor’s cryptocurrency wallet technology.
Yet customers ultimately experience the consequences regardless of which company actually lost control over their information. A phishing email bearing Trezor’s identity still damages trust even when the underlying compromise occurred somewhere else.
The repeated incidents show why third-party security has become inseparable from a company’s own cybersecurity posture. Strong internal protection offers limited comfort when trusted providers can expose audiences or give attackers legitimate channels for contacting them.
For Trezor customers, future messages deserve greater scrutiny even when the sender information appears technically authentic and familiar. Requests involving wallet backups should immediately be treated as malicious regardless of urgency, branding, or apparent email authentication.
The Trezor data breach is therefore bigger than another cryptocurrency phishing campaign targeting people with fake security warnings. It shows how several vendor compromises can gradually build the information and credibility attackers need to target valuable customers more effectively.