Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-12 ยท updated: 2026-09-12 ยท tags: [incident, financial-services, breach, phishing, supply-chain] ยท confidence: high ยท severity: high ยท affected_sectors: [financial-services] ยท au_impact: true

Trezor has disclosed that the compromise of Brevo, its third-party marketing platform, exposed roughly 347,000 email addresses in its opt-in newsletter database and led to phishing attacks against a subset of them, with about 2,500 customers clicking the malicious link before the phishing domain was taken down within 20 minutes. Brevo reported that an unauthorised actor gained access to its systems and used them to send mail from 120 customer accounts; the Trezor-branded messages claimed a "hardware microcontroller vulnerability" in the STM32 chips used in Trezor cold-storage wallets could expose seeds to brute-force cracking, and directed recipients to download an app that requested their wallet backup. No other Trezor system was touched, and the company has suspended the Brevo account. The disclosure is the second time Trezor customer data has reached attackers through a third-party service โ€” a support ticketing portal breach in January 2024 exposed roughly 66,000 users' details โ€” and it turns the supply-chain phishing wave covered in yesterday's digest into a quantified first-party disclosure with a named intermediary and a count of affected addresses.

Attribute Detail
Sector Financial Services
Date 2026-09-12
Source BleepingComputer
Reliability Tier 2
Breach classification Confirmed breach