The Phishing Email Really Came From Trezor. That Was the Problem.

The sender was legitimate. The message was not. A Brevo compromise let an attacker use Trezor's newsletter channel to distribute a wallet-backup phishing lure.

The sender was legitimate. The message was not. A Brevo compromise let an attacker use Trezor's newsletter channel to distribute a wallet-backup phishing lure.

Trezor says ShipMonk retained data it had promised to delete, exposing another 67,000 US customers to phishing and potential physical-security risk.