Trezor warns of phishing campaign affecting 347k newsletter subscribers after email provider compromise

A breach at Trezor's third-party email marketing platform, Brevo, allowed attackers to send phishing emails to roughly 347,000 newsletter subscribers. The messages falsely claimed a hardware vulnerability in Trezor wallets and directed users to a malicious app that requested wallet backup information. Trezor took down the phishing domain within 20 minutes, limiting the impact to 2,500 users who clicked the link.
The attack originated from a compromise of Brevo, affecting 120 accounts, which allowed unauthorized emails to be sent under Trezor's name. Trezor disabled the phishing domain within twenty minutes, though 2,500 subscribers had already clicked the malicious link before it was neutralized.
This incident adds to Trezor's history of third-party vendor breaches. Previously, a 2024 support portal hack exposed data from 66,000 users, and a recent ShipMonk logistics breach compromised order details for 81,000 customers, which later prompted extortion emails from the ShinyHunters gang.
This breach highlights the cascading risks of relying on third-party vendors for critical communications. Affected subscribers, particularly cryptocurrency holders, may face heightened susceptibility to future phishing attempts, as their email addresses are now known to attackers. If any of the 2,500 clickers entered their wallet backups, their digital assets could be stolen. This incident could also erode trust in hardware wallet security communications, prompting users to seek more direct verification channels.