Thousands of cryptocurrency holders received phishing emails on 9 September 2026 after attackers gained access to customer accounts at the email service provider Brevo and used them to send messages from the legitimate domains of Trezor, CoinTracking and BitBox. CoinTracking named Brevo as the source; Brevo confirmed that an attacker had access to 120 customer accounts and used that access to mail the clients' contact bases, and said the access has been closed and a full post mortem will follow.
| Attribute | Detail |
|---|---|
| Root cause | Compromise of email service provider Brevo (120 customer accounts accessed) |
| Victims | Trezor, CoinTracking, BitBox โ and other firms sharing the same newsletter provider |
| Pretexts | Trezor: "Critical Security Alert: STM32 Entropy Vulnerability"; CoinTracking: "Data Breach Notice: Please refresh API Keys" |
| Delivery | Sent from the vendors' own legitimate sending domains |
| Reported | 2026-09-10 |
Recipients reported the messages looked convincing enough that several clicked through to near-identical phishing sites. Trezor said it had taken down the domain and was investigating how the attackers obtained access to its legitimate sending domain; BitBox sent a warning to all newsletter subscribers, contacted the provider and reported the phishing domains, noting most links had already been taken down. Trezor was separately breached earlier in 2026, exposing the personal details of 81,000 customers, and multiple breaches at crypto hardware and software vendors have raised concern about the exposure of identifying information on digital-asset holders โ DOJ prosecutors have noted that criminals ranked targets using lists of crypto owners stolen from crypto companies. The incident is a clean example of supply-chain trust abuse: the brand was not breached, but the intermediary that held its contact list was.