Trezor alerts users to massive phishing sweep following Brevo email breach
Trezor, a leading hardware‑wallet provider, has warned that a coordinated phishing campaign this week targeted 347,000 of its customers after a separate breach at email‑service firm Brevo exposed large volumes of contact data. At least 2,500 recipients clicked a malicious link embedded in the fraudulent messages, prompting the company to issue an urgent advisory.
The breach at Brevo – formerly known as Sendinblue – was disclosed earlier in the month and involved the theft of millions of email addresses and associated credentials. Cybercriminals quickly repurposed the harvested information, crafting emails that mimicked official Trezor communications and urged recipients to verify their accounts through a provided link.
The deceptive messages directed users to a counterfeit login page designed to capture wallet passwords and two‑factor authentication codes. While Trezor has not confirmed any direct loss of funds, the company cautions that anyone who entered credentials on the fake site should assume their account security may be compromised and take immediate remedial steps.
In response, Trezor sent a mass notification to its user base, recommending password changes, activation of two‑factor authentication, and a thorough review of recent account activity. The firm also emphasized that hardware wallets remain secure so long as private keys never leave the device, and it is working with law‑enforcement agencies to trace the perpetrators.
Security analysts note that the incident underscores how email remains a prime attack vector for cryptocurrency users, especially when third‑party services are breached. The episode serves as a reminder that even well‑known brands can be impersonated, and that users must verify the authenticity of any unsolicited request for login details.
Looking ahead, Trezor says it will strengthen its communication protocols, including exploring signed email verification and tighter monitoring of phishing trends. The company urges all users to stay vigilant, report suspicious messages, and regularly update security settings to mitigate future threats.
Comments (0)
Be the first to comment.
Join the discussion