Brevo Hack Exposes 347,000 Trezor Users to Phishing Scam Targeting Crypto Wallets
A Dangerous Email Scam Unfolds
According to НВ — Техно: Cybercriminals infiltrated the email marketing platform Brevo, sending approximately 347,000 phishing emails aimed at cryptocurrency holders by pretending to be communications from the hardware wallet maker Trezor. Trezor confirmed that attackers gained access to 138 Brevo accounts linked to their company. Alarmingly, the attackers’ access was not properly restricted, inadvertently allowing them to reach all organizations tied to those accounts.
The fraudulent emails contained links prompting recipients to download an app requesting the password for their wallet backup. One such email carried the subject line, 'Critical Security Alert: STM32 Entropy Vulnerability.' Using the stolen passwords, hackers could irreversibly drain funds from the victims’ public blockchain wallets.
Impact and Ongoing Risks
Although Trezor’s hardware wallets, products, and account systems were not compromised, the company is reevaluating its partnerships with service providers and warning customers about potential follow-up phishing attempts. This incident follows a similar breach in August involving Trezor’s logistics partner ShipMonk, which exposed personal data of at least 81,000 wallet buyers, including names, phone numbers, and email and mailing addresses.
Following that breach, affected customers received emails containing QR codes that directed them to counterfeit websites designed to steal crypto wallet passwords.
These events highlight the escalating danger of phishing attacks targeting cryptocurrency users and underscore the critical need for vigilance when handling emails, especially those asking for sensitive information.
The frequency of hacks and phishing schemes impacting crypto-related services is rising, emphasizing the urgent need for enhanced security protocols. Crypto owners are strongly advised to verify the authenticity of any communication before submitting private credentials. This situation also stresses the importance of continuous security monitoring and improvements throughout all interactions with digital assets.
Read also

