Hardware wallet firm Trezor confirmed that a data breach at its marketing vendor, Brevo, exposed 347,000 customer emails. Attackers used these details to launch phishing campaigns attempting to steal wallet recovery phrases. This second third-party security incident this year raises concerns about vendor data management and the safety of user information.
Trezor, a leading provider of hardware wallets, has reported a significant security incident affecting its customers following a data breach at its third-party email marketing provider, Brevo. The breach, which occurred on September 9, 2026, allowed unauthorized actors to gain access to Trezor’s marketing account by exploiting a privilege escalation flaw in Brevo’s login system.
Approximately 347,000 email addresses of newsletter subscribers were exposed during the incident. Attackers used this contact information to send targeted phishing emails, disguised as critical security alerts regarding an 'STM32 Entropy Vulnerability.' These fraudulent messages directed users to a malicious website specifically designed to harvest wallet recovery phrases. Trezor reported that it managed to take the malicious domain offline within 20 minutes, limiting the impact to roughly 2,500 users who had clicked the link before the site was disabled.
This incident is distinct from Trezor's internal infrastructure, which the company confirmed remains secure. Trezor emphasized that its hardware wallet security, firmware, and private key management architecture were not compromised. However, the event serves as a stark reminder of the risks companies face when relying on third-party service providers. For businesses and technology users alike, this creates a dependency where security is only as strong as the vendor tasked with handling sensitive contact data.
Adding to user concerns is that this is the second major data exposure for Trezor customers in recent months. An earlier breach in August 2026 involving the logistics partner ShipMonk resulted in the exposure of physical addresses and contact information for 81,000 customers. The cumulative effect of these leaks has heightened the risk of social engineering and, more severely, the potential for physical coercion, often referred to as 'wrench attacks,' where bad actors use exposed personal information to target individuals for their digital assets.
For investors and industry observers, these incidents highlight a growing critical monitorable: third-party vendor due diligence. As companies increasingly outsource marketing, logistics, and data management, the ability to secure these secondary channels has become a central part of operational risk. Users are advised to remain vigilant, as the contact information exposed in these breaches often remains a target for future phishing attempts and fraudulent physical mailings. The company continues to conduct reviews of its vendor relationships to mitigate further exposure.
