Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor warns of phishing attacks targeting 347,000 users after a Brevo breach.
Intelligence analysis by Qwen 2.5 (3B)

Trezor, a hardware wallet company, has warned of a phishing attack targeting 347,000 users following a security incident at its email provider, Brevo.
Trezor, a company that makes special wallets for storing money, had a problem with their email service. A bad person got into their email service and sent fake emails to people. These emails tricked people into clicking a link that could let the bad person get their money. Trezor found out about this and fixed the problem quickly.
Analysis
{"heading_1":"The Brevo Incident","paragraph_1":"The total number of affected users in the ShipMonk incident was initially reported as 14,000, but a follow-up investigation found that the breach affected an additional 67,000 U.S. customers, bringing the total to 81,000 individuals.","paragraph_2":"Trezor has also received extortion emails from the ShinyHunters extortion gang following the ShipMonk breach. The company has suspended the Brevo account to stop further email distribution.","paragraph_3":"Trezor's phishing email campaign used fake 'critical security alert' emails claiming that a 'hardware microcontroller vulnerability' in Trezor cold storage wallets' STM32 microcontrollers could expose users' seeds to brute-force cracking. The emails tricked recipients into clicking a malicious link that asked them to enter their wallet backup.","heading_2":"Previous Breaches","heading_3":"Impact and Response"}
Key points
- Trezor warned of a phishing attack targeting 347,000 users following a security incident at its email provider, Brevo.
- The incident affected roughly 347,000 email addresses in Trezor's opt-in newsletter database.
- Trezor took down the domain used in the phishing attacks within 20 minutes, limiting the impact to 2,500 customers who clicked the malicious link before it was taken down.
- Trezor has disclosed data breaches in the past, including a breach after its third-party support ticketing portal was hacked and another after threat actors hacked its logistics and shipping provider.
- Trezor has also received extortion emails from the ShinyHunters extortion gang following the ShipMonk breach.
This incident highlights the importance of using secure email services and strong passwords. It also shows that companies are taking steps to secure their systems and warn users of potential threats.
This breach shows that even companies with strong security measures can still be vulnerable. It also raises concerns about the safety of email services and the potential for future attacks.



