deniz.in

Markets

Weather

Loading weather

· via TechCrunch

Trezor hit by second vendor breach in two months as Brevo hack fuels mass crypto phishing

Hackers used compromised Brevo accounts to push roughly 347,000 phishing emails to Trezor customers, weeks after a ShipMonk breach exposed the addresses of wallet buyers.

Trezor hit by second vendor breach in two months as Brevo hack fuels mass crypto phishing

What happened

Hardware wallet maker Trezor is warning customers for the second time in two months that a company it relies on was hacked, according to TechCrunch. In a blog post this week, Trezor said a cyberattack on Brevo, a marketing technology firm it uses to send newsletters, allowed attackers to push around 347,000 phishing emails to Trezor customers, each carrying a malicious link disguised as an official message from the wallet maker.

Trezor stressed that none of its products, wallets, or its own account system were affected. The damage was confined to the mailing pipeline and, by extension, to the inboxes of its customers.

How the phishing campaign works

According to TechCrunch, tapping the link in the phishing emails downloads an app that asks the victim to enter their wallet backup password. One subject line used in the campaign read "Critical Security Alert: STM32 Entropy Vulnerability" — a technical-sounding lure designed to make recipients act before they think.

The stakes in this kind of scam are unusually high. With a stolen wallet password, a hacker can irreversibly drain a person's funds from the public blockchain. There is no chargeback and no fraud department, which is exactly why crypto holders are such attractive targets for phishing operators.

What Brevo said

Brevo disclosed in an incident status post that the attackers gained access to 138 Brevo accounts and used them to send the mass of phishing messages. The company said the hackers abused a flaw that left their access far broader than it should have been: permissions intended for a limited scope were effectively granted across every organization those accounts could reach, sweeping Trezor's mailing lists into the blast.

The earlier ShipMonk breach

This is not an isolated slip. In August, Trezor told customers that one of its shipping partners, the fulfilment company ShipMonk, had suffered a data breach. According to TechCrunch, that incident exposed the names, phone numbers, email addresses and postal addresses of at least 81,000 people who bought and received Trezor hardware.

The ShipMonk breach has already produced its own follow-on campaign. In the weeks since, some people have received physical letters by post claiming to be from Trezor, containing a QR code that opens a fake page built to harvest wallet passwords.

Why it matters

Two things make this story bigger than a routine phishing wave.

First, it is a textbook case of third-party risk. Trezor's hardware and account systems were never touched, yet hundreds of thousands of its customers were endangered because a marketing vendor and a shipping partner were compromised. For any company handling sensitive customer data, the real security perimeter now extends to every supplier that stores records on its behalf.

Second, the combination of leaked postal addresses and known crypto ownership raises physical safety concerns. As TechCrunch notes, the breach could put crypto owners and other wealthy individuals at risk of so-called wrench attacks, where criminals use physical violence to force victims into handing over passwords rather than cracking the technology itself.

Trezor says it is reevaluating its relationships with its vendors, and it has warned customers that their email addresses may be reused for future phishing attempts. For Trezor owners, the practical takeaway is blunt: treat any unsolicited message — email or post — that asks for a wallet backup password as hostile by default, and verify security alerts through official channels rather than embedded links or QR codes.

  • #crypto
  • #phishing
  • #data-breach
  • #security
  • #hardware-wallets

Related posts