Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked.
By Dillip Chowdary β’ Oct 04, 2026 β’ Source: BleepingComputer
What broke in 347
BleepingComputer reports: Trezor: 347,000 users targeted in phishing attacks after Brevo breach. Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]
Who is exposed by 347
The phishing emails tried to trick recipients into clicking a malicious link that prompted them to download an app that asked them to enter their wallet backup. Trezor says that it took down the domain used in the phishing attacks within 20 minutes, disabling the link and limiting the campaign's impact to 2,500 customers who had clicked it before it was taken down.

Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
What to do now about 347
An unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's," the company said. These addresses might be potentially used for other phishing attacks in the future.
How the 347 issue works
While Trezor initially said the incident affected nearly 14,000 customers, a follow-up investigation found that the resulting breach affected an additional 67,000 U.S. See the full write-up from BleepingComputer via the source link for quotes and complete context.
What is still unknown about 347
The company said that the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026. Since then, BleepingComputer also learned that ShipMonk received extortion emails from the ShinyHunters extortion gang following the breach.
Developer Action Items
- β Inventory whether Trezor users targeted phishing runs in prod, CI, staging, or on laptops before you debate severity.
- β Confirm the vendor's fixed build for Trezor users targeted phishing from BleepingComputer, then schedule the patch window.
- β If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
- β Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
- β Treat unexpected emails that mention Trezor users targeted phishing (shipping, invoices, password resets) as phishing until verified.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Advertisement