Trezor marketing platform was breached, 347,000 users received phishing emails
Bitcoin hardware wallet manufacturer Trezor has warned that its third-party marketing platform Brevo, used for sending newsletters, experienced a data breach, with attackers using the platform to send phishing emails to 347,000 Trezor customers. The attackers sent emails using Trezor's domain, making the phishing attempt more deceptive, with malicious links encouraging users to download applications and enter wallet backups.
Trezor stated that it shut down the domain at the DNS level within 20 minutes to prevent the links from remaining active, but approximately 2,500 people had already clicked on them. Trezor has suspended its Brevo account to stop further emails from being sent and emphasized that other Trezor systems were not affected aside from the marketing platform, while reminding users that Trezor never asks customers for wallet backups.
Prior to this incident, Trezor disclosed last month that its third-party fulfillment partner ShipMonk was attacked, resulting in the data breach of 11,742 customers; last week it also reported that the names, emails, phone numbers, shipping addresses, and order numbers of another 67,000 U.S. customers were exposed in the breach. This year, cryptocurrency wallet Ledger's payment processor Global-e and wallet provider SafePal have also experienced data breaches, with approximately 39,800 customers' order information at SafePal being accessed without authorization.






