Massive Phishing Attack Targets Crypto Users After Brevo Breach Exposes 347,000 Subscribers
September 10, 2026
A coordinated phishing campaign circulated to followers of Trezor, BitBox, and CoinTracking, linked to a Brevo breach that exposed roughly 347,000 newsletter subscribers.
Trezor warned that a legitimate-looking security alert about an entropy vulnerability did not come from them, and hackers gained access to their third‑party email domain, complicating phishing detection.
BitBox and CoinTracking were affected in the broader incident, with BitBox reporting unauthorized emails sent through the compromised provider and ongoing investigations into the scope.
Trezor emphasized ongoing challenges securing third‑party services used for communications and the need for customers to verify notices directly from the company.
Observers note the broader implications of third‑party data breaches for crypto holders and outline continued steps by Trezor to address security risks.
While BitBox and CoinTracking have disclosed impacts, they have not fully named Brevo as the source, though Brevo’s involvement is acknowledged in reporting.
Trezor confirmed that none of its products, wallets, or core account systems were affected by the Brevo breach.
Experts warn that AI-enabled vulnerability discovery is accelerating, heightening urgency for crypto firms to secure communications and the software supply chain.
Phishing efforts included attempts to harvest data or backups, with strong guidance to never enter wallet backups online and to confirm actions physically on devices.
Brevo provided a postmortem, and Cointelegraph sought comment but did not receive a response before publication.
Earlier breaches at related firms show how exposed customer data can enable more convincing phishing, though wallet keys remained secure.
Security guidance reiterates that anyone with a wallet’s recovery seed can move funds, underscoring the need to keep seeds private and verify communications through official channels.
Summary based on 10 sources
Get a daily email with more Tech stories
Sources

Bitcoin Magazine • Sep 10, 2026
Trezor Reveals Another Data Breach
Cointelegraph • Sep 11, 2026
Brevo login flaw enabled phishing email targeting 347K Trezor subscribers
Decrypt • Sep 9, 2026
Bitcoin Wallet Maker Trezor Says Hackers Breached Its Email Provider