Up Headlines

Startup News

Trezor Data Breach Exposes Hundreds of Thousands to Phishing

3 min read
Trezor Data Breach Exposes Hundreds of Thousands to Phishing

Hardware wallet maker Trezor has issued another warning to customers after a cyberattack on one of its service providers exposed customer data and enabled scammers to target hundreds of thousands of crypto users.

The breach involved Brevo, a marketing technology company that Trezor uses to distribute newsletters. According to Trezor, attackers compromised Brevo’s systems and used the access to send approximately 347,000 phishing emails to Trezor customers.

The emails included malicious links designed to look like official Trezor communications. One of the subject lines reportedly read: “Critical Security Alert: STM32 Entropy Vulnerability.”

The scam becomes dangerous when a recipient clicks the link. It downloads an application that asks the user to enter their wallet backup password. If a hacker obtains that password, they may be able to access the victim’s wallet and steal their cryptocurrency. Because blockchain transactions are generally irreversible, stolen funds can be extremely difficult—or impossible—to recover.

How the Breach Happened

Brevo said in an incident status update that attackers gained access to 138 Brevo accounts, allowing them to distribute a large volume of phishing messages.

The company explained that the attackers exploited a flaw in how access permissions were managed. Their access was not properly limited, meaning it was incorrectly granted to organizations that the compromised accounts could reach.

The incident underscores a growing security challenge for crypto companies: even when their own systems remain secure, attackers can target outside vendors that handle customer communications, shipping, payments, or other essential services.

Trezor emphasized that its own products, wallets, and account systems were not affected by the Brevo incident. However, the exposed customer information still creates risks for users, particularly because email addresses can be used in convincing follow-up scams.

A Second Breach in Recent Weeks

This is not the first recent security incident involving Trezor’s service providers. In August, the company warned customers that a breach at its shipping partner, ShipMonk, had exposed personal information belonging to at least 81,000 people who had purchased and received Trezor hardware wallets.

The data reportedly included names, phone numbers, email addresses, and postal addresses.

Such information can expose crypto owners and other wealthy individuals to more than online fraud. Security experts have long warned that leaked personal details can increase the risk of targeted violence and so-called “wrench attacks,” in which criminals use physical force to try to obtain wallet passwords or access to funds.

Following the ShipMonk breach, some customers reportedly received physical letters pretending to be from Trezor. The letters included QR codes that directed recipients to fake websites designed to steal their crypto wallet passwords.

Trezor Warns of More Phishing Attempts

Trezor said it is reassessing its relationships with vendors following the incidents. The company also warned customers that their email addresses could be used in future phishing campaigns.

Users should treat unexpected messages claiming to require wallet security updates with caution. Trezor has repeatedly reminded customers that wallet backup passwords, recovery phrases, and private keys should never be entered into websites or applications reached through unsolicited links.

Also read : The Boring Company Raises $3B at $23B Valuation

Copyright © Up Headlines. All rights reserved. | Supported by eOffice4U.