Brevo Security Breach Exposes 347,000 Crypto Users to Phishing Attacks
A security breach at Brevo's email platform has exposed hundreds of thousands of cryptocurrency users to phishing attacks. The incident, which was discovered on September 9, 2026, allowed a malicious actor to compromise 138 customer accounts and send fake emails to approximately 347,000 Trezor newsletter recipients.
The attacker exploited an authentication vulnerability in Brevo's platform to gain access to the email subscriber databases of several companies, including Trezor, BitBox, and CoinTracking. The phishing messages were designed to appear legitimate and included links that directed users to a counterfeit application.
Trezor has confirmed that its wallet information, login credentials, and product infrastructure remained secure throughout the incident. However, the company is now considering all 347,000 addresses as potentially compromised and vulnerable to subsequent phishing campaigns.