Illustrative image generated with AI
Trezor Phishing Campaign Abused Trusted Email Infrastructure After Brevo Breach
Trezor phishing emails sent via breached Brevo targeted 347K users with fake STM32 flaw to steal wallet seeds. Learn how SAML failure enabled attack.
Text generated by artificial intelligence, published without human review. AI transparency
A convincing security alert reached roughly 347,000 addresses
A phishing campaign reported on September 10, 2026 targeted Trezor customers through newsletter infrastructure operated by third-party email provider Brevo. The fraudulent messages appeared to come from [email protected], giving recipients few of the usual reasons to distrust the sender.
The email carried the subject line Critical Security Alert: STM32 Entropy Vulnerability. It claimed that a weakness in STM32 microcontrollers used by Trezor hardware wallets could expose wallet seeds to brute-force attacks.
That warning was fabricated. Trezor said the messages were unauthorized and did not reflect a genuine vulnerability disclosure from the company. There is no evidence that attackers compromised Trezor devices, their cryptographic protections, or the STM32 hardware itself.
According to SecurityWeek’s account of the incident, approximately 347,000 Trezor email addresses stored in the Brevo account were targeted. Around 2,500 recipients clicked the embedded link before the phishing website was disabled, approximately 20 minutes after detection.
The number of victims who submitted sensitive information remains unknown. Trezor has not disclosed confirmed cryptocurrency losses or said how many people entered recovery details into the phishing page.
The combination of a trusted sender domain, an urgent hardware-security claim, and a website designed to resemble a legitimate cryptocurrency service made the campaign unusually persuasive. This was not merely bulk spam with a forged display name. It exploited access to an established communications channel.
The fake STM32 flaw was designed to steal wallet backups
The phishing message attempted to create fear around entropy generation, a technical concept that directly affects cryptographic key security. By claiming that STM32 components produced vulnerable wallet seeds, the attackers gave recipients a plausible reason to take immediate action.
The malicious site then sought wallet backup information. Technical details about its implementation, hosting infrastructure, data-handling code, and exact input fields have not been disclosed.
The intended outcome is nevertheless clear: obtaining a recovery seed would allow an attacker to reconstruct the victim’s wallet and transfer its assets. Such transactions can be irreversible, even if the victim quickly discovers the fraud.
A legitimate wallet provider should never require a user to enter a recovery phrase, private key, PIN, or authentication code into a website reached through an unsolicited email. The security of a hardware wallet cannot protect funds once its recovery secret has been voluntarily supplied to an attacker.
Trezor warned recipients not to follow the link and took down the malicious domain. It also began investigating both the provider compromise and the mechanism that allowed attackers to send through its legitimate-looking email identity.
No CVE identifier has been assigned or disclosed for the Brevo vulnerability. Affected Brevo software versions, if versioning is applicable to the hosted service, are also not known.
A SAML authorization failure enabled cross-organization access
Brevo attributed the underlying compromise to an implementation error in its Security Assertion Markup Language Single Sign-On system. SAML SSO lets a service rely on an external identity provider to authenticate users, but it must also restrict what each authenticated identity can access.
The attacker first created a Brevo account and enabled SSO for it. Legitimate Brevo users were then invited into the attacker-controlled SSO configuration.
Using its own identity provider, the attacker authenticated as those invited users. The critical failure occurred after authentication: Brevo did not correctly limit access to the organization for which that SSO configuration had been enabled.
Instead, the attacker could reach every Brevo organization available to the impersonated users. In effect, a trust relationship created for one tenant became a route into unrelated customer environments.
This distinction matters. Authentication established who the platform believed the user was, while faulty authorization determined which organizations that identity could enter. The latter control failed to preserve tenant boundaries.
Brevo said unauthorized access ultimately affected 138 customer accounts. Six were used to send phishing messages, while contact information was exported from 43 accounts. An earlier notice cited 120 affected customer accounts, but the later technical postmortem raised that figure to 138.
Brevo reported removing the attacker, closing the unauthorized access path, and deploying a permanent correction for the SAML authorization-scoping problem. The company also said it intended to cooperate with law-enforcement authorities.
CoinTracking and BitBox were caught in the same provider incident
Trezor was not the only cryptocurrency company whose subscribers received malicious mail. CoinTracking and BitBox also confirmed campaigns involving their newsletter audiences, according to reporting on the affected cryptocurrency businesses.
CoinTracking identified Brevo as its provider and reported a message titled Data Breach Notice: Please refresh API Keys as soon as possible. That lure attempted to direct recipients to a malicious link under the pretext of securing their API credentials.
Compromised API keys could expose portfolio data or permit unauthorized operations, depending on the permissions granted to each key. Confirmed losses and the number of affected CoinTracking recipients are not known.
BitBox warned newsletter subscribers, contacted its provider, reported phishing domains, and said that most associated links appeared to have been removed. It did not disclose how many recipients were targeted or publicly identify Brevo in the cited statement.
The multi-company impact shows why marketing platforms are valuable targets. One authorization flaw can expose mailing lists from numerous customers while also providing access to delivery systems that recipients already trust.
Email authentication controls may not stop such messages when the attacker is operating through authorized infrastructure. From the receiving server’s perspective, the message can look substantially more legitimate than ordinary domain spoofing.
Earlier data exposures increase the risk of tailored attacks
The Brevo campaign follows a separate Trezor-related breach involving ShipMonk, the company’s shipping and logistics provider. Trezor disclosed that incident in August.
An initial estimate placed the affected population at approximately 14,000 customers. An update dated September 4 added 67,000 customers in the United States, bringing the reported total to 81,000.
Exposed records included full names, email and shipping addresses, telephone numbers, and order information. Customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom were affected when their orders had been placed between May 10 and August 8, 2026.
Breach notifications said attackers exploited a critical SQL-injection zero-day in the Metabase analytics platform within ShipMonk’s environment. The flaw reportedly enabled administrator access and data theft. No CVE identifier or affected Metabase versions have been provided.
ShipMonk also received extortion emails from the ShinyHunters group, according to BleepingComputer’s report on the incidents. That attribution has not been independently established in the other cited reporting.
Some Trezor customers subsequently received malicious QR codes by postal mail. Physical addresses and order records can help criminals distinguish actual cryptocurrency owners from people who merely subscribed to a newsletter.
This is not Trezor’s first third-party exposure. In January 2024, attackers compromised its external support-ticketing portal, exposing names, usernames, and email addresses belonging to roughly 66,000 users.
Information from separate breaches can be combined. An attacker with a person’s name, wallet-related purchase history, telephone number, address, and email can construct far more credible impersonation, extortion, or account-recovery schemes.
The consequences can also extend beyond online fraud. Identifying cryptocurrency holders and their physical locations creates a risk of burglary, coercion, and so-called wrench attacks.
What recipients and organizations should do now
Anyone who received the STM32-themed email should treat it as malicious, regardless of whether it appeared under the Trezor domain. The embedded link should not be opened or revisited.
Users who entered a recovery phrase must assume that the wallet secret is compromised. Moving assets to a newly created wallet with a new recovery seed is safer than merely changing a PIN, because the old seed remains sufficient to reconstruct the wallet.
Recipients should also:
- Review wallet and exchange histories for unauthorized transactions.
- Rotate passwords and API keys entered after following suspicious links.
- Revoke unnecessary API permissions and active sessions.
- Enable strong multifactor authentication wherever it is supported.
- Open wallet and exchange services through known applications or manually typed official addresses.
- Distrust follow-up calls, letters, QR codes, or “recovery” services referencing the incident.
Organizations using Brevo or similar marketing platforms should audit SAML trust relationships and confirm that authorization is enforced separately for every tenant and organization. They should invalidate sessions and tokens, review administrative activity, and determine whether contact lists were accessed or exported.
Monitoring should also cover campaigns sent through legitimate domains, not only obvious spoofing attempts. In this incident, the authenticity of the delivery channel was part of the attack. The security warning itself was the deception.
Sources
This article is an original reworking based on the sources below.
