MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-11 · via TechCrunch

Trezor warns of phishing wave after third-party email vendor breach

Image via TechCrunch
Image via TechCrunch

Hardware wallet maker Trezor disclosed that a cyberattack on its email marketing provider Brevo allowed hackers to send roughly 347,000 phishing emails to customers. The malicious link prompted users to enter their wallet backup password, which could lead to irreversible theft of funds. This is the second breach affecting Trezor's third-party vendors in recent months, following an earlier incident involving shipping partner ShipMonk.

Expanded Detail

The attack exploited a flaw in Brevo's permission settings, enabling unauthorized access to 138 accounts. The fraudulent emails referenced a specific hardware vulnerability and directed recipients to a malicious app designed to capture their wallet recovery phrase, which would grant full control over their cryptocurrency.

This marks the second vendor-related incident for Trezor, following a ShipMonk breach that exposed personal details of over 81,000 customers. That leaked information has already spawned physical mail scams with QR codes, and could enable criminals to target wealthy individuals for physical coercion to obtain their passwords.

Context

This recurring pattern of third-party breaches could significantly undermine trust in hardware wallets, as users may question whether their personal data is truly secure. Affected customers face the immediate risk of irreversible financial theft if they fall for the phishing app, while the leaked shipping data may expose them to physical coercion or targeted home invasions. The incident underscores the broader challenge of securing complex supply chains in the crypto ecosystem.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at TechCrunch →
Related stories
Crypto Wallet Maker Alerts Customers to Phishing Emails After Vendor Compromise · Cybersecurity
Trezor warns of phishing campaign affecting 347k newsletter subscribers after email provider compromise · Cybersecurity
Trezor breach expands to 81,000 customers after logistics partner's data retention failure · Cybersecurity
Healthcare tech firm reports data exposure via third-party vendor credentials · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider.” Browse more stories.