INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Trezor users targeted in phishing attacks after Brevo breach incident
| 2026-09-11 07:55 CRITICAL LOW DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
On September 9, 2026, Trezor's third-party marketing platform Brevo suffered a security incident affecting 120 accounts, allowing an unauthorized actor to send emails from various customer accounts, including Trezor's. This breach led to phishing attacks targeting approximately 347,000 email addresses of customers who opted in to receive newsletters. The attackers claimed that a "hardware microcontroller vulnerability" could expose seeds to brute-force cracking, tricking recipients into clicking malicious links. As a result, around 2,500 users clicked the link before it was taken down by Trezor within 20 minutes. This incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
Technical Mitigations AI-generated
• Patch the STM32 microcontroller vulnerability in Trezor cold storage wallets using a patch from the official Trezor website.
• Block phishing emails with fake "critical security alert" messages and links to malicious downloads, specifically targeting email addresses associated with Brevo's compromised accounts.
• Use a reputable antivirus solution that can detect and block zero-day vulnerabilities like Metabase SQL injection attacks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
he•••@tr•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORDICS
NORDICS
FIVE_EYES
FIVE_EYES
logisticslogistics
Incident Timeline
January 2024
Trezor disclosed a data breach in January 2024 after its third-party support ticketing portal was hacked, resulting in the theft of user data from approximately 81,000 individuals.
Click on any entity below to view its context and source!
tactic
Data Breach
"
In January 2024, Trezor
disclosed another data breach
after its third-party support ticketing portal was hacked and attackers stole data (including names, usernames, and email addresses) from roughly 66,000 users.
victims
66,000 users
"
In January 2024, Trezor
disclosed another data breach
after its third-party support ticketing portal was hacked and attackers stole data (including names, usernames, and email addresses) from roughly 66,000 users.
victims
14,000 customers
While Trezor initially said the incident affected
nearly 14,000 customers
, a follow-up investigation found that the resulting breach affected
an additional 67,000 U.S. customers
, bringing the total to 81,000 individuals.
victims
67,000 additional U.S. customers
While Trezor initially said the incident affected
nearly 14,000 customers
, a follow-up investigation found that the resulting breach affected
an additional 67,000 U.S. customers
, bringing the total to 81,000 individuals.
August 8, 2026
Threat actors ShinyHunters sent extortion emails to ShipMonk after the Brevo breach.
Click on any entity below to view its context and source!
organisation
BleepingComputer
Since then, BleepingComputer also learned that ShipMonk received extortion emails from the ShinyHunters extortion gang following the breach.
threat_actor
ShinyHunters
Since then, BleepingComputer also learned that ShipMonk received extortion emails from the ShinyHunters extortion gang following the breach.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
2026/08/12
Threat actors exploited a Metabase SQL injection zero-day vulnerability in ShipMonk's systems to steal customers' sensitive data before targeting 347,000 Trezor users with phishing attacks.
Click on any entity below to view its context and source!
industry
Logistics
Trezor also
disclosed a data breach
last month after threat actors hacked ShipMonk, its logistics and shipping provider, using a critical
Metabase SQL injection zero-day vulnerability
, and stole customers' order data, including full names, shipping addresses, email addresses, and phone numbers.
tactic
Data Breach
Trezor also
disclosed a data breach
last month after threat actors hacked ShipMonk, its logistics and shipping provider, using a critical
Metabase SQL injection zero-day vulnerability
, and stole customers' order data, including full names, shipping addresses, email addresses, and phone numbers.
organisation
ShipMonk
Trezor also
disclosed a data breach
last month after threat actors hacked ShipMonk, its logistics and shipping provider, using a critical
Metabase SQL injection zero-day vulnerability
, and stole customers' order data, including full names, shipping addresses, email addresses, and phone numbers.
September 9, 2026
Trezor users whose email addresses were leaked following the Brevo breach are being targeted in phishing attacks.
between May 10 and August 8, 2026
Threat actors used phishing attacks to target approximately 347,000 Trezor users who received orders between May 10 and August 8, 2026.
Click on any entity below to view its context and source!
target_region
Brazil
The company said that the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Colombia
The company said that the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Italy
The company said that the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Portugal
The company said that the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
Sweden
The company said that the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
target_region
United Kingdom
The company said that the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
2026/09/11
Threat actors used phishing emails claiming a hardware microcontroller vulnerability to trick 347,000 Trezor users into downloading an app that asked for wallet backup information.
Click on any entity below to view its context and source!
organisation
Brevo
Trezor: 347,000 users targeted in phishing attacks after Brevo breach.
victims
347,000 users
Trezor: 347,000 users targeted in phishing attacks after Brevo breach.
organisation
Trezor
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link.
victims
2,500 users
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link.
Trezor says that it took down the domain used in the phishing attacks within 20 minutes, disabling the link and limiting the campaign's impact to 2,500 customers who had clicked it before it was taken down.
Tactical Metrics
Metrics
victims
347,000
Users
Click for context!
Trezor: 347,000 users targeted in phishing attacks after Brevo breach.
Metrics
victims
2,500
Users
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link.
Trezor says that it took down the domain used in the phishing attacks within 20 minutes, disabling the link and limiting the campaign's impact to 2,500 customers who had clicked it before it was taken down.
Metrics
victims
66,000
Users
"
In January 2024, Trezor
disclosed another data breach
after its third-party support ticketing portal was hacked and attackers stole data (including names, usernames, and email addresses) from roughly 66,000 users.
Metrics
victims
14,000
Customers
While Trezor initially said the incident affected
nearly 14,000 customers
, a follow-up investigation found that the resulting breach affected
an additional 67,000 U.S. customers
, bringing the total to 81,000 individuals.
Metrics
victims
67,000
Additional U.S. Customers
While Trezor initially said the incident affected
nearly 14,000 customers
, a follow-up investigation found that the resulting breach affected
an additional 67,000 U.S. customers
, bringing the total to 81,000 individuals.
Intelligence Sources
BleepingComputer
2026-09-11
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:20
Comprehensive Tactical Telemetry
Highly Correlated Entities
6x
target region
Target Country
Brazil
country
6x
organisation
Identified Entity
ShipMonk
entity
5x
timeline
Temporal Reference
between May 10 and August 8, 2026
date
3x
tactic
Cyber Operation Type
Data Breach
tactic
3x
victims
Users
347,000
users
Contextual Telemetry
Context Block
7 METRICS
industry
Targeted Sector
Logistics
sector
general metric
Email Addresses
347,000
email addresses
general metric
Minutes
20
minutes
threat actor
APT Group
ShinyHunters
actor
victims
Customers
14,000
customers
victims
Additional U.S. Customers
67,000
additional u.s. customers
general metric
Individuals
81,000
individuals
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.