Skip to main content
AVOID.NET

Trezor Email Provider Breach (Brevo, September 2026)

avoid.net/trezor-email-provider-breach-brevo-september-202622/100·87% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5FUUAD…76nT

Summary

On September 9, 2026, attackers exploited a SAML SSO misconfiguration at Brevo, Trezor's third-party email marketing provider, to access 138 Brevo customer accounts and send phishing emails to approximately 347,000 Trezor newsletter subscribers. The messages falsely claimed a critical STM32 microcontroller entropy vulnerability required users to re-enter their seed phrases; approximately 2,500 users clicked the malicious link before Trezor disabled the phishing domain within 20 minutes. No cryptocurrency losses have been confirmed as of mid-September 2026, but the incident forms part of a pattern of third-party supply-chain attacks targeting Trezor users across multiple vendor relationships.

Connected Entities

4 entities · 60 linked investigations
Organizations
Trezor Email Provider Breach (Brevo, September 2026)Trezor57Solana62ShipMonk
Relationships
  • Trezor Email Provider Breach (Brevo, September 2026)mentioned withShipMonk(70%)
  • Trezor Email Provider Breach (Brevo, September 2026)mentioned withSolana(70%)
  • Trezor Email Provider Breach (Brevo, September 2026)mentioned withTrezor(70%)
  • Trezormentioned withSolana(75%)
  • ShipMonkmentioned withTrezor(80%)

Connected Through

3 shared actors · 404 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about Trezor Email Provider Breach (Brevo, September 2026)?

Timeline(11 events)

1 April 2022

Mailchimp, a prior Trezor email marketing provider, suffered a social engineering attack that exposed approximately 100 Trezor user accounts and enabled a targeted phishing campaign.

The Register

10 August 2026

ShipMonk, Trezor's shipping and logistics vendor, notified Trezor that customer data was exposed via a Metabase SQL injection zero-day (CVE-2026-72898, CVSS 10.0).

Trezor official blog

13 August 2026

Trezor publicly disclosed the ShipMonk breach, initially reporting approximately 13,689 affected customers with names, emails, phone numbers, and shipping addresses exposed.

BleepingComputer

9 September 2026

Attackers exploited Brevo's SAML SSO misconfiguration, accessed 138 Brevo customer accounts, and sent phishing emails to approximately 347,149 Trezor newsletter subscribers. The emails used the subject line 'Critical Security Alert: STM32 Entropy Vulnerability' and directed recipients to a malicious application requesting seed phrase entry.

Trezor official blog

10 September 2026

Brevo detected the SSO access at 6:30 AM UTC and closed the attack vector by 8:30 AM UTC. Trezor disabled the phishing domain within approximately 20 minutes of detection, by which time approximately 2,500 users had clicked the malicious link. Brevo force-signed out all platform users and deployed a permanent SSO scope-restriction fix.

Brevo Status incident write-up

11 September 2026

TechCrunch reported that Trezor confirmed the Brevo data breach and described it as the second data breach of a Trezor third-party vendor within weeks.

TechCrunch

12 September 2026

Solana Mobile disclosed that its Brevo marketing email account had been accessed without authorization as part of the same Brevo incident and warned users of elevated phishing risk.

CryptoBriefing

13 September 2026

Solana Mobile confirmed it had suspended its Brevo marketing email account following unauthorized access.

The Daily Hodl

14 September 2026

In a separate secondary attack, attackers used a hardcoded Cloudflare API key to deploy a malicious Cloudflare Worker on Brevo's domains and customer-embedded JavaScript files between approximately 16:05 and 20:13 UTC, injecting ClickFix malware and WordPress backdoor payloads across an estimated 100,000+ customer websites.

SecurityWeek

15 September 2026

All malicious subdomains from the September 14 Cloudflare Worker attack stopped resolving. Brevo's JavaScript files were confirmed clean.

BleepingComputer

17 September 2026

Trezor updated its disclosure to confirm 347,149 total marketing contacts were affected by the Brevo breach. No confirmed cryptocurrency losses from the phishing campaign were reported as of this date.

Trezor official blog
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 19 of 20 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/18/2026, 5:09:04 PM

last updated: 9/18/2026, 8:24:20 PM

avoid.net — verified advice for a post-truth world