Hardware wallet manufacturer Trezor disclosed a security incident affecting its email marketing infrastructure on Wednesday, marking the company's third data breach in recent weeks. An unauthorized actor compromised Brevo, the third-party platform Trezor uses for customer communications, enabling scammers to send phishing emails to approximately 347,000 customers.
Details of the Security Incident
The breach allowed attackers to exploit Trezor's domain name, lending credibility to fraudulent messages titled "Critical Security Alert: STM32 Entropy Vulnerability." The phishing emails directed recipients to download a malicious application and enter their wallet backup phrases—credentials that would grant attackers complete access to users' cryptocurrency holdings.
Trezor's security team responded by disabling the malicious domain at the DNS level within 20 minutes of detection. However, approximately 2,500 individuals had already clicked the fraudulent link before the company could intervene. The company emphasized that no other Trezor systems were compromised and has suspended its Brevo account to prevent additional unauthorized communications.
Pattern of Third-Party Vulnerabilities
This incident represents the third security breach affecting Trezor customers in recent weeks, though each originated from external service providers rather than Trezor's core infrastructure. Last month, shipping partner ShipMonk suffered a breach exposing data from 11,742 customers. A subsequent disclosure revealed an additional 67,000 U.S. customers had their personal information—including names, emails, phone numbers, and shipping addresses—compromised in the same incident.
Implications for Crypto Security Professionals
These recurring breaches underscore growing demand for cybersecurity specialists within crypto organizations, particularly professionals experienced in third-party risk management and vendor security assessments. Companies across the blockchain sector face similar challenges, with competitors Ledger and SafePal experiencing comparable incidents this year involving payment processors and customer databases.
For professionals working in crypto security roles, these events highlight the critical importance of supply chain security protocols and the need for organizations to implement robust vendor oversight frameworks. The pattern suggests increased hiring demand for security architects, compliance specialists, and risk management professionals capable of evaluating and monitoring third-party service providers in the digital asset space.


