Trezor announced Wednesday that an unauthorized actor gained access to Brevo, a third-party customer communication platform, and sent phishing emails to 347,000 users. The attackers utilized Trezor’s domain name to enhance credibility, distributing messages titled 'Critical Security Alert: STM32 Entropy Vulnerability' that contained malicious links prompting users to download an app and enter their wallet backups. Trezor stated it suspended the Brevo account and took down the domain at the DNS level within 20 minutes, limiting initial clicks to 2,500 individuals before the link became inactive.
This incident follows recent security disclosures involving other service providers. Last month, Trezor reported that data from 11,742 customers was exposed after its fulfillment partner ShipMonk was targeted. Subsequently, the company revealed that an additional 67,000 U.S. customers had personal details, including names, emails, phone numbers, shipping addresses, and order numbers, leaked in that breach. Trezor emphasized that no other internal systems were touched during the Brevo incident and reiterated that it never requests wallet backups from customers.
The compromise of a third-party marketing infrastructure highlights a persistent vulnerability in the crypto supply chain, where operational dependencies on external vendors create attack surfaces distinct from core product security. By leveraging a trusted domain for phishing, attackers bypassed technical defenses through social engineering, demonstrating that brand reputation itself can be weaponized when vendor controls fail. The rapid containment measures, including DNS takedowns and account suspension, indicate mature incident response protocols, yet the exposure of contact data remains a significant risk factor for future targeted campaigns.
Industry observers should note the clustering of similar incidents across major hardware wallet providers, including Ledger and SafePal, which suggests systemic weaknesses in how crypto firms manage third-party data flows. While Trezor confirmed no direct system breaches occurred, the accumulation of leaked personal information across multiple vendors increases the sophistication of potential follow-up attacks. Monitoring how these companies adjust vendor vetting processes and communicate ongoing risks to users will be critical for assessing long-term trust and compliance standards.


