Trezor announced Wednesday that an unauthorized actor gained access to Brevo, a third-party customer communication platform, and sent phishing emails to 347,000 users. The attackers utilized Trezor’s domain name to enhance credibility, distributing messages titled 'Critical Security Alert: STM32 Entropy Vulnerability' that contained malicious links prompting users to download an app and enter their wallet backups. Trezor stated it suspended the Brevo account and took down the domain at the DNS level within 20 minutes, limiting initial clicks to 2,500 individuals before the link became inactive.

This incident follows recent security disclosures involving other service providers. Last month, Trezor reported that data from 11,742 customers was exposed after its fulfillment partner ShipMonk was targeted. Subsequently, the company revealed that an additional 67,000 U.S. customers had personal details, including names, emails, phone numbers, shipping addresses, and order numbers, leaked in that breach. Trezor emphasized that no other internal systems were touched during the Brevo incident and reiterated that it never requests wallet backups from customers.