Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 10, 2026, Trezor confirmed that its email marketing provider, Brevo, had been compromised. The incident exposed contact data for hundreds of thousands of customers and triggered a highly targeted phishing wave.
This is the second incident in two months for the hardware wallet maker. In August, shipping partner ShipMonk had already exposed data for at least 81,000 customers. The two breaches are not causally linked, but together they trace a pattern: for self-custody users, the supply chain of third-party SaaS services has become the most vulnerable attack perimeter.
- Brevo confirmed that 138 accounts were compromised via a flaw in SAML SSO management, with 6 accounts used to send phishing and 43 used to export contacts.
- Trezor received and forwarded 347,000 emails with the subject "Critical Security Alert: STM32 Entropy Vulnerability" to its customers; DNS takedown of the malicious domain occurred within 20 minutes, limiting clicks to roughly 2,500.
- The emails passed SPF, DKIM, and DMARC checks because they were generated from legitimate infrastructure, making the threat technically indistinguishable from authentic communications.
- CoinTracking and BitBox suffered similar campaigns, indicating the target was the broader crypto wallet ecosystem, not Trezor in isolation.
How Brevo's SAML SSO Mechanism Works
The attacker created a Brevo account and enabled Single Sign-On authentication. They then invited legitimate platform users and, through their own identity provider, authenticated while impersonating them.
According to Brevo's postmortem, the access was not "properly scoped": instead of being limited to the single SSO organization where it was enabled, it "wrongly granted" access to all organizations reachable by the invited users. This allowed lateral movement across different tenants.
The brief does not specify whether the SAML protocol, if implemented correctly, would have prevented this behavior by design. What primary sources document is an authorization boundary error in Brevo's specific implementation, not a vulnerability in the protocol itself.
Brevo's Response: Numbers and Timeline
Brevo identified the incident at 06:30 UTC on September 10, 2026. By 08:30 UTC, it had closed the attacker's route and forced a sign-out of all users.
"Customers trust us with access to their audiences, and in this case we failed to protect it." — Brevo postmortem
Of the 138 compromised accounts, 6 were used to send phishing emails, 43 suffered contact exports, and 93 showed no significant activity. Brevo has not publicly disclosed details of any structural remediation measures beyond closing the unauthorized access.
The Trezor Campaign: Techniques, Numbers, and Timing
The email sent on September 10, 2026 carried the subject "Critical Security Alert: STM32 Entropy Vulnerability." It contained a link to a malicious application that requested a wallet backup.
The technical lure — an alleged vulnerability in the STM32 microcontroller — was chosen to maximize credibility with a technically sophisticated audience. According to Trezor's official advisory, the initial email was sent to 347,000 customers.
The destination domain was disabled at the DNS level within 20 minutes. Trezor limited clicks to approximately 2,500 people and subsequently contacted all recipients to inform them of the risk.
Why the Emails Weren't Blocked: The Weapon Is Legitimacy
Emails generated during the attack passed standard authentication checks — SPF, DKIM, DMARC — because they originated from authentic, authorized Brevo infrastructure. There was no sender spoofing to filter: the message arrived technically from Trezor's legitimate provider.
This characteristic makes the attack particularly insidious for any inbound filtering system. The chain of trust was not broken at the perimeter, but at the source.
CoinTracking confirmed that its customers were also targeted with emails titled "Data Breach Notice: Please refresh API Keys as soon as possible." BitBox suffered analogous phishing without confirming the provider involved. The brief does not document whether other companies were affected.
The Double-Breach Pattern and Physical Context
The Brevo breach follows the ShipMonk incident by a few weeks, where shipping data for at least 81,000 Trezor customers was exposed. After that incident, some individuals received physical letters containing malicious QR codes.
According to The Record, the cybersecurity community signals growing concern over so-called "wrench attacks" — physical coercion of those who hold private keys — especially when shipping data exposes the identity and residence of digital asset holders.
Trezor stated it is reevaluating vendor relationships. It warned that exposed email addresses could be reused for future phishing attacks. The identity of the attacker or criminal group responsible does not emerge from available sources.
What Changes
Per editorial analysis, the Brevo-Trezor case raises a structural question for the self-custody model. Hardware wallets are designed to eliminate trust in third parties, yet users must still trust the providers that manage communications, shipping, and updates.
The brief documents that Trezor is reevaluating vendor relationships. It does not specify remediation measures adopted by Brevo beyond closing the attack route and forcing sign-out. Primary sources do not provide general operational advisories on how users should verify their providers' SSO configurations.
For hardware wallet users, the case highlights a non-eliminable constraint: even the most secure device remains exposed to compromise of the communication channel linking it to the vendor. The security of self-custody depends on the security of the supply chain that supports it.
Information has been verified against cited sources and is current as of publication.
Sources
- https://techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/
- https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach
- https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider
- https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE/write-up
- https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
- https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/
- https://jingletree.com/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider-267726.html
- https://www.europesays.com/3245413/
- https://primanews.org/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/
- https://this.weekinsecurity.com/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.