INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Trezor users targeted in phishing attacks after Brevo breach incident

| 2026-09-11 07:55 CRITICAL LOW DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
On September 9, 2026, Trezor's third-party marketing platform Brevo suffered a security incident affecting 120 accounts, allowing an unauthorized actor to send emails from various customer accounts, including Trezor's. This breach led to phishing attacks targeting approximately 347,000 email addresses of customers who opted in to receive newsletters. The attackers claimed that a "hardware microcontroller vulnerability" could expose seeds to brute-force cracking, tricking recipients into clicking malicious links. As a result, around 2,500 users clicked the link before it was taken down by Trezor within 20 minutes. This incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.
Technical Mitigations AI-generated
• Patch the STM32 microcontroller vulnerability in Trezor cold storage wallets using a patch from the official Trezor website. • Block phishing emails with fake "critical security alert" messages and links to malicious downloads, specifically targeting email addresses associated with Brevo's compromised accounts. • Use a reputable antivirus solution that can detect and block zero-day vulnerabilities like Metabase SQL injection attacks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

he•••@tr•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORDICS NORDICS FIVE_EYES FIVE_EYES logisticslogistics
Incident Timeline
‎January 2024
Trezor disclosed a data breach in January 2024 after its third-party support ticketing portal was hacked, resulting in the theft of user data from approximately 81,000 individuals.
tactic Data Breach
victims 66,000 users
victims 14,000 customers
victims 67,000 additional U.S. customers
‎August 8, 2026
Threat actors ShinyHunters sent extortion emails to ShipMonk after the Brevo breach.
organisation BleepingComputer
threat_actor ShinyHunters
organisation NFL
organisation CHANEL
‎2026/08/12
Threat actors exploited a Metabase SQL injection zero-day vulnerability in ShipMonk's systems to steal customers' sensitive data before targeting 347,000 Trezor users with phishing attacks.
industry Logistics
tactic Data Breach
organisation ShipMonk
‎September 9, 2026
Trezor users whose email addresses were leaked following the Brevo breach are being targeted in phishing attacks.
‎between May 10 and August 8, 2026
Threat actors used phishing attacks to target approximately 347,000 Trezor users who received orders between May 10 and August 8, 2026.
target_region Brazil
target_region Colombia
target_region Italy
target_region Portugal
target_region Sweden
target_region United Kingdom
‎2026/09/11
Threat actors used phishing emails claiming a hardware microcontroller vulnerability to trick 347,000 Trezor users into downloading an app that asked for wallet backup information.
organisation Brevo
victims 347,000 users
organisation Trezor
victims 2,500 users
Tactical Metrics
Metrics
victims
347,000
Users
Metrics
victims
2,500
Users
Metrics
victims
66,000
Users
Metrics
victims
14,000
Customers
Metrics
victims
67,000
Additional U.S. Customers
Intelligence Sources