Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
- ID
- 23493
- Status
- summarized
- Published
- 11 Sep 2026, 9:32 PM
- Fetched
- 11 Sep 2026, 10:28 PM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/09/11/scammers-target-hundreds-of-thousands-of-crypto-owners-after-trezor-confirms-data-breach-of-email-provider/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 3.5
- Created
- 11 Sep 2026, 10:29 PM
- Tags
- Audience
- saas_foundersdevelopers
What happened
Hackers exploited a scoping flaw in Brevo, an email marketing platform Trezor uses for newsletters, to send ~347,000 phishing emails impersonating Trezor. The phishing emails used a fake 'Critical Security Alert' subject line and linked to a malicious app that steals wallet backup passwords, enabling irreversible blockchain fund theft. This is Trezor's second third-party breach in two months, following an August breach at shipping partner ShipMonk that exposed personal data of at least 81,000 hardware wallet buyers.
Why it matters
If you use Brevo (or any third-party email/marketing provider) to send customer communications, this is a concrete reminder that a vendor-side access control flaw can turn your sender reputation into a phishing channel targeting your users. SaaS founders shipping physical products should also note the ShipMonk breach pattern: your logistics and marketing vendors are now part of your attack surface, and a compromise there can expose customer PII and enable highly targeted social engineering.
Discussion angle
How do you vet and monitor third-party vendors (email, shipping, payments) for access-control weaknesses before they become your breach — and what would you tell customers if your newsletter provider were used to phish them?