Trezor's Brevo breach: your email vendor can send as you
Attackers used Trezor's own Brevo account to phish 347,000 subscribers with authenticated email. Your ESP is a sending identity, not just a tool.
On September 9, roughly 347,000 Trezor newsletter subscribers got a convincing security warning from Trezor. It was not from Trezor. An attacker got into Brevo, the third-party email platform Trezor uses, and sent the phishing campaign through Trezor's own account. SPF, DKIM, DMARC — all of it passed, because the mail was genuinely sent by Trezor's email service provider. That is the detail every operator running a list should sit with.
What actually happened
Per Trezor's own notice, an unauthorized actor reached Brevo's system and used it to send mail from various customer accounts — 120 Brevo accounts in total. The message carried the subject "Critical Security Alert: STM32 Entropy Vulnerability," claimed a hardware flaw in the microcontrollers used in Trezor wallets, and pushed recipients to download an app that asked for their wallet backup.
Trezor's response was fast: the phishing domain was killed at the DNS level within about 20 minutes, the Brevo account was suspended, and warnings went up across their channels. Roughly 2,500 people clicked before the domain went down, per BleepingComputer. No Trezor product, wallet, or account system was touched.
This is the second vendor incident at Trezor in a month. We wrote about the ShipMonk fulfillment breach in August. Different vendor, different data, same perimeter problem.
Why your ESP matters more than your mail server
Most small operators think about their email vendor as deliverability plumbing. It is not. It is a sending identity you have delegated, and it carries your domain's entire accumulated trust. When it is misused, none of your authentication records help — they certify the sender, and the sender was legitimate.
Four things worth doing this week.
Turn on SSO and enforce MFA in the ESP itself. Treat that console like your bank, not like a marketing tool. Audit who still has a login from a role they left.
Cap the blast radius. Most platforms let you limit sending volume, restrict which lists an account can address, and require approval before a broadcast goes out. Defaults are usually wide open.
Pre-write the correction. Trezor's 20 minutes was good because somebody had thought about it in advance. Decide now who kills the domain, who posts the notice, and where it goes — status page, social, banner on the site.
Set the expectation before you need it. Tell customers in advance that you will never ask for credentials, seeds, or payment details over email. A one-line standing promise makes the fake obvious.
Twenty minutes, roughly 2,500 clicks. That ratio is what a fast response buys you. The slower version of this story costs you the list.
Key takeaways
- An attacker reached Brevo and sent phishing mail from customer accounts, hitting about 347,000 Trezor subscribers on September 9
- Trezor reports 120 Brevo customer accounts were used; no Trezor product, wallet, or account system was affected
- Because the mail came from Trezor's real ESP account, SPF, DKIM and DMARC all passed
- Trezor took the phishing domain down at DNS within roughly 20 minutes; about 2,500 people had already clicked
- This is Trezor's second vendor-side incident in a month, after the ShipMonk fulfillment breach in August
- Enforce MFA and SSO on the ESP console, cap send volume and list scope, and pre-write the correction notice
Who can send email as your brand right now? We map every vendor holding a piece of your customer relationship, lock down the ones that can speak as you, and build the incident playbook before you need it. See how we harden the commerce stack, or send us your vendor list.
Sources: Trezor: Security incident at Brevo, our third-party email provider, BleepingComputer: Trezor: 347,000 users targeted in phishing attacks after Brevo breach.
- #vendor-risk
- #phishing
- #email-marketing
- #data-breach
- #ecommerce
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Prime Video Shop the Scene: 8,000 titles, one buy button
Amazon expanded Prime Video shopping to 8,000+ titles and launched Shop the Scene visual search. What it means for sellers whose product data has to win the match.
Read itMaven Robotics raised $100M. It has eight robots deployed.
Maven Robotics exits stealth with a $100M Series A, a $1T market claim, and eight robots in production. The gap is the lesson for anyone scoping automation.
Read it