Importante: los artículos de nuestro blog de momento solo están disponibles en inglés.

News

Security incident at Brevo, our third-party email provider

Trezor Team
Trezor Team
Sharing insights on crypto, security & self-custody
3 mins de lectura
Sep 10, 2026

On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts. An unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's.

The incident affected our opt-in newsletter database, roughly 347,000 email addresses. These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched. We have suspended the Brevo account to stop further email distribution.

The phishing email sent from our account contained a malicious link that prompted users to download an app that asked users to enter their wallet backup.

The email subject line was: Critical Security Alert: STM32 Entropy Vulnerability

Do not click on any link; doing so could result in a loss of funds.

Blog_BREVOPHISHING_EMAIL_2000x1000.jpg

The initial email was sent to 347,000 customers, all of whom have been contacted to inform them of the risk.

We took down the domain at the DNS level within 20 minutes, preventing the link from working for anyone else and limiting access to 2,500 people who had clicked it before we took it down. This is possible because Brevo routes all communication via our domain. The email-sending function was also disabled to prevent further phishing emails.

Warning messaging has been added to Trezor.io, Trezor Suite, community and support channels, direct email notifications, and other channels.

Important: If you receive a suspicious email from Trezor, please take the following steps:

  • Do not click any links or provide any personal information.
  • Delete the email from your inbox promptly.
  • If you have entered your wallet backup in any form, especially through a link provided in such emails, immediately move your funds to a new wallet.

If you have not entered your wallet backup anywhere other than on your Trezor device during recovery, your assets remain secure.

Please be careful of any email claiming to be from Trezor. We will never contact you asking for your wallet backup.

We’re truly sorry for any concern this may have caused you. Our team is actively handling the incident, and further updates will be provided as necessary.

Blog_BREVOPHISHING_TIMELINE_2000x1300 (1).jpg

Your questions, answered (FAQs)

Was Trezor itself hacked?

No. This was a breach of Brevo, the third-party platform Trezor uses for newsletter emails. No Trezor product, wallet, or account system was affected.

What data was exposed?

We cannot confirm whether the list itself was exported. Until we hear more from Brevo, we're treating all roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for phishing. Brevo's system holds no passwords, wallet data, or other personal information.

I clicked the link but didn't enter anything. Am I at risk?

No. The risk only applies if you entered your wallet backup into the app or anywhere online. Clicking the link alone doesn't expose your funds.

I entered my wallet backup after clicking the link. What do I do?

Move your funds to a new wallet immediately.

Why does Trezor use a third-party provider for newsletters instead of handling it in-house?

Most companies at our scale use a dedicated email platform to send newsletters, it handles deliverability, unsubscribes, and list management in ways an in-house system usually can't match. We're reviewing our vendor relationships and security requirements in light of this incident.

Trezor Team
Trezor Team
Sharing insights on crypto, security & self-custody
Articles written by Trezor's team members.

¡Suscríbete al boletín de Trezor!

Recibe ofertas exclusivas, novedades de productos y análisis sobre criptomonedas directamente en tu bandeja de entrada.
Al hacer clic en “Suscribirse”, aceptas que Trezor Company s.r.o. utilice tu dirección de correo electrónico únicamente para enviarte su boletín informativo. Puedes darte de baja en cualquier momento mediante el enlace incluido en cada correo. Para saber cómo gestionamos tus datos, consulta la Política de privacidad de Trezor.