Trezor has warned that a data breach at the third-party marketing platform it uses for sending newsletters is leading criminals to target customers with phishing attacks.
The top hardware wallet manufacturer said Wednesday that an unauthorized actor got access to Brevo’s system and sent emails to 347,000 Trezor customers. Brevo is a platform businesses use to send customer communications.
Scammers managed to use Trezor’s domain name to send the email, making the phishing attempt all the more believable. The email contained a malicious link asking users to download an app and enter their wallet backup.
Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating…
The news comes after Trezor last month announced that data from 11,742 customers had been exposed after its third-party fulfillment partner, ShipMonk, was targeted.
It then said last week that an additional 67,000 U.S. customers had their names, emails, phone numbers, shipping addresses and order numbers leaked in the breach.
“We took down the domain at the DNS level within 20 minutes, preventing the link from working for anyone else and limiting access to 2,500 people who had clicked it before we took it down,” Trezor said on Wednesday.
“These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched,” Trezor added.
“We have suspended the Brevo account to stop further email distribution.”
Trezor reminded users that it never asks customers to ask for their wallet backups.
Criminals have been targeting data this year, with scammers getting hold of customer information via crypto wallet Ledger’s payment processor Global-e to send phishing emails.
Crypto wallet provider SafePal last month also announced a data breach that involved unauthorized access to about 39,798 customers’ order information, including personal details such as names, addresses and purchase data.
Bimbo Bakeries USA (BBU) has revealed that attackers gained access to files containing names and Social Security numbers by exploiting a zero-day vulnerability in Oracle E-Business Suite (EBS), which a third-party vendor uses. The company confirmed the unauthorized access in December 2025 but did not identify the existence of Social Security numbers until August 2026. […]
Mathspace, an online mathematics learning platform used by schools in Australia and New Zealand, has reported a data breach affecting 1,079,819 students, parents or guardians, teachers, and staff members. The company stated that attackers exploited a critical vulnerability in its self-hosted Metabase reporting environment, allowing them to gain administrator-level access without legitimate credentials. Mathspace Data […]
Natural Resources Wales (NRW) has reported a personal data breach involving sensitive diversity-monitoring information from both former and current employees. The breach affected individuals whom NRW employed between April 2013 and March 2018. An internal investigation revealed that a spreadsheet containing employee data was accidentally published online, making the information accessible before the issue was […]
Deleting files is easy, but making sure those files cannot be recovered later requires a different approach. A normal file deletion operation usually removes filesystem references while leaving the underlying data in place. That allows operating systems to delete files quickly, but it also means recovery software can sometimes retrieve information from previously used storage space.
Hardware wallet manufacturer Trezor has said that a data breach first announced last month is worse than originally reported.
The Prague, Czech Republic-based company said Friday that an additional 67,000 U.S. customers had their names, emails, phone numbers, shipping addresses and order numbers leaked. The leaked data came from orders made between November 2019 and August 2021, according to Trezor.
Trezor first announced in August that data from 11,742 customers from the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal had been exposed — with names, emails, phone numbers and shipping addresses leaked.
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.
Another 67,000 customers from the US who ordered between November 2019 and August 2021… https://t.co/yDQvTlAA2S
Another 1,947 customers just had their names, cities and emails exposed in the breach.
In Friday’s announcement, Trezor said that its third-party fulfillment partner, ShipMonk, had falsely reassured the company about deleting customer data.
In a statement to Bitcoin Magazine, a Trezor spokesperson said: “We had no reason to expect it: throughout our entire relationship with ShipMonk we repeatedly requested and received written assurance confirming the deletion of that data, in line with our contract, our data policy and our past communications.”
“It should not have existed to be exposed,” the statement added.
ShipMonk did not immediately responded to Bitcoin Magazine’s questions.
Trezor first announced in August that the data had been leaked because ShipMonk experienced “unauthorized access to their systems containing customer data.”
The company added that it had directly emailed all customers involved in the breach. Trezor’s parent company, SatoshiLabs, told Bitcoin Magazine last month that it was investigating the incident.
Trezor is one of the most popular Bitcoin hardware wallet solutions, and also has support for storing other cryptocurrencies.
Bitcoiners’ personal data has been targeted by cybercriminals in the past: back in 2020, an unauthorized party accessed popular hardware manufacturer Ledger’s e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers.
At the start of this year, customers reported receiving emails from Global-e, Ledger’s payment partner, that a data breach at its cloud systems leaked sensitive customer data.
This piece has been updated to include additional commentary from Trezor.
Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000 additional US customers. This significantly broadens the scope of an incident initially reported in August. The newly identified data pertains to Trezor orders processed during a prior partnership with ShipMonk, which lasted from November 2019 […]
An identity theft search site claimed to have more than 150 million driver's license photos stolen from an ID verification service. The crime site has now shut down.
In January, the Cloud Security Alliance asked security professionals how they handle the identities on which their AI systems run. Fewer than a quarter of organizations had a documented, formally adopted policy for creating or removing one. More than 16% do not track when a new identity is created at all. Those identities hold tokens [...]
The company, which distributes medicines and medical devices to hospitals and healthcare practices across the U.S., said it was hacked and expects intermittent service degradation.