The Phishing Email Really Came From Trezor. That Was the Problem.
Update, 21 September 2026: Brevo says the actor returned four days after the phishing incident through a separate, long-lived Cloudflare API key. For roughly five and a half hours, malicious code reached Brevo-hosted scripts embedded on customer websites. The new findings and their limits are incorporated below.
A phishing email sent to roughly 347,000 newsletter addresses did not merely copy Trezor’s branding or forge a sender name. It was distributed through the legitimate newsletter channel Trezor used at Brevo. About 2,500 recipients clicked before the malicious domain was disabled. The app behind the link asked for the one secret a hardware wallet is designed to keep offline: the wallet backup.
Trezor says its wallets, products and account systems were not breached. The incident occurred at Brevo, a third-party marketing platform used for newsletter campaigns. Trezor is treating roughly 347,000 opt-in newsletter addresses as known to the attacker, although it cannot yet confirm that the list itself was exported.
The malicious message used a real customer account
Brevo says an actor exploited a weakness in its handling of SAML single sign-on on 10 September and accessed 138 customer accounts. Six accounts were used to send phishing, while contacts were exported from 43. One of the affected accounts belonged to Trezor.
The Trezor message used the subject line “Critical Security Alert: STM32 Entropy Vulnerability”. Its link prompted recipients to download an application that asked them to enter their wallet backup. Trezor disabled sending and took the destination domain down at DNS level within 20 minutes.
No cryptocurrency theft has been confirmed in Trezor’s notice. Clicking the link alone did not expose funds, according to the company. The danger applied to anyone who installed the malicious application and entered a wallet backup.
Closing the phishing path did not close every supplier credential
On 14 September, Brevo says the actor returned through a compromised, long-lived Cloudflare API key. The key was used to deploy a Cloudflare Worker that injected code into brevo.com, sibforms.com and three JavaScript files that Brevo customers embed in their own websites.
The malicious code showed selected visitors a false Cloudflare verification page and instructed them to paste and run a command, a social-engineering method commonly called ClickFix. On WordPress sites where a Brevo widget was embedded, the script also attempted to install and run a plugin when the visitor was logged in as an administrator.
Brevo says the Worker remained active for about five and a half hours before it removed the code and revoked the key and related credentials. The company’s investigation found that the key had first been misused in late August, but it found no malicious injection into customer-facing pages before 14 September.
The 100,000-site figure is an estimate, not a victim count
Security company Sansec estimates that more than 100,000 websites were likely affected because they embedded the relevant Brevo scripts. That number describes potential delivery reach. It does not prove that every site served the malicious response, that every visitor saw the lure or that every prompted command was executed.
The distinction is operationally important. Website owners must still investigate because a compromised administrator session could have allowed the injected script to install a WordPress plugin. Visitors who followed the false verification instructions may have compromised their own devices even if the website itself was not altered permanently.
What Trezor users should still do
- Never enter a wallet backup because an email asks. Trezor says it will never request this secret.
- Move funds if the backup was entered. Create a new wallet with a new backup and transfer assets from a known-clean device.
- Expect follow-up phishing. Treat incident-themed refunds, firmware updates and account checks as untrusted until independently verified.
- Preserve suspicious messages. Retain headers and report the lure through an official support route.
What websites using Brevo should check
- Identify every embedded Brevo script. Record where it ran and which administrator sessions were active during the exposure window.
- Review WordPress changes. Look for unfamiliar plugins, new administrators, scheduled tasks, modified files and outbound connections.
- Investigate visitors who saw ClickFix. A pasted command is an endpoint incident even if the website now appears clean.
- Rotate supplier credentials deliberately. Include API keys, Workers, DNS controls and delegated integrations rather than stopping at interactive SSO sessions.
- Plan an independent shutdown path. Organisations need a way to disable compromised third-party scripts without waiting for the supplier.
The first incident showed that an authentic email channel can carry a hostile message. The second showed that closing one identity path is not enough when long-lived machine credentials still connect the supplier to customer websites. Both failures came from trusted infrastructure behaving exactly as an attacker wanted.
Sources
- Trezor, security incident at Brevo, published 10 September 2026.
- Brevo status and incident material, reviewed 21 September 2026.
- SecurityWeek, Brevo supply-chain attack reporting, published 18 September 2026 at 05:46 ET.


