Trezor, the hardware crypto wallet maker, is warning customers that a cyberattack on Brevo, a marketing tech company used by Trezor, has led to the sending of around 347,000 phishing emails. These emails, disguised as alerts from Trezor, contain a malicious link aimed at stealing users' wallet backup passwords.
According to Trezor, one email subject line warned of a 'Critical Security Alert: STM32 Entropy Vulnerability,' prompting users to click and download an app. With the right password, a hacker can access and steal funds from the victim's wallet on the public blockchain.
Bessaging company Brevo disclosed that 138 of its accounts were compromised, allowing hackers to launch a mass phishing campaign. Brevo noted that the hackers abused a flaw in the system, gaining access to all organizations they could reach, despite the access being wrongly granted.
This incident is the second recent security breach for Trezor. In August, the company warned that a data breach at its shipping partner, ShipMonk, exposed the personal details of at least 81,000 customers. Following the ShipMonk incident, some individuals received fake Trezor letters with QR codes designed to steal their wallet passwords.
Trezor is urging customers to be vigilant and is reevaluating its relationships with vendors. The company warns that email addresses could be used in future phishing attacks, highlighting the ongoing risk to crypto owners and wealthy individuals.







