{"id":377575,"date":"2026-09-11T07:56:00","date_gmt":"2026-09-11T14:56:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/en\/?p=377575"},"modified":"2026-09-11T07:56:36","modified_gmt":"2026-09-11T14:56:36","slug":"trezor-warns-of-brevo-phishing-attack-347000-fake-emails-sent","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/trezor-warns-of-brevo-phishing-attack-347000-fake-emails-sent\/","title":{"rendered":"Trezor warns of Brevo phishing attack: 347,000 fake emails sent"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Trezor says a phishing campaign tied to Brevo sent <strong>roughly 347,000 fake emails<\/strong> to people subscribed to Trezor\u2019s newsletter. One of the messages carried the subject line \u201cCritical Security Alert: STM32 Entropy Vulnerability.\u201d<\/p>\n\n<p class=\"wp-block-paragraph\">Those emails tried to funnel people to a malicious app or a fake webpage that asked for <strong>a backup password<\/strong>, wallet password, or recovery seed. Trezor says its hardware wallets, products, core internal systems, and account systems were not directly compromised. The real damage came from impersonation made possible by stolen contact data.<\/p>\n\n<p class=\"wp-block-paragraph\">Brevo says attackers got into <strong>138 customer accounts<\/strong>, then took advantage of an access-control flaw where permissions were \u201cnot properly scoped.\u201d That gave them access across organizations and turned what could have been a limited breach into a much broader spam and phishing campaign.<\/p>\n\n<p class=\"wp-block-paragraph\">If you use a Trezor wallet, take this seriously. Recovery seeds are still <strong>the real prize<\/strong> here, because anyone who gets one can usually empty the wallet, and those transactions usually can\u2019t be reversed.<\/p>\n\n<p class=\"wp-block-paragraph\">This comes right after Trezor\u2019s recent ShipMonk breach. Trezor later updated that incident to say it affected <strong>about 81,000 customers<\/strong>, including roughly 67,000 additional US customers. The exposed records dated back to November 2019 and included names, email addresses, phone numbers, and shipping addresses, which raises the risk of impersonation and even wrench attacks.<\/p>\n\n<p class=\"wp-block-paragraph\">Trezor says some customers have already reported fraudulent letters, QR-code scams, and other unsolicited contact. Its warning is posted through <strong>Trezor\u2019s official channels<\/strong>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Trezor says a phishing campaign tied to Brevo sent roughly 347,000 fake emails to people subscribed to Trezor\u2019s newsletter. One of the messages carried the subject line \u201cCritical Security Alert: STM32 Entropy Vulnerability.\u201d Those emails tried to funnel people to a malicious app or a fake webpage that asked for a backup password, wallet password, &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/trezor-warns-of-brevo-phishing-attack-347000-fake-emails-sent\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Trezor warns of Brevo phishing attack: 347,000 fake emails sent&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9349,"featured_media":377574,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-377575","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/377575","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9349"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=377575"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/377575\/revisions"}],"predecessor-version":[{"id":377576,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/377575\/revisions\/377576"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/377574"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=377575"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=377575"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=377575"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=377575"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=377575"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=377575"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}