Hardware cryptocurrency wallet manufacturer Trezor has suffered a second data security incident in as many months, this time originating from a compromised third-party marketing vendor. A cyberattack on Brevo allowed threat actors to dispatch hundreds of thousands of fraudulent emails to crypto owners.
The malicious messages directed recipients to fake links designed to download software aimed at stealing wallet backup passwords. Although Trezor maintains that its core wallet infrastructure and products remain uncompromised, the incident highlights persistent vulnerabilities associated with relying on external service providers.
As digital asset holders face rising risks of targeted scams, Trezor is currently re-evaluating its vendor relationships and urging customers to remain extremely cautious regarding unsolicited communications.
- Marketing platform Brevo suffered a security breach exposing Trezor customer data.
- Roughly 347,000 phishing emails were sent to trick users into revealing wallet passwords.
- Trezor’s hardware and internal account systems were not directly breached.
- This marks the second vendor-related data exposure for the company in recent weeks.
Sources:
