Hardware crypto wallet maker Trezor has warned customers that a cyberattack on marketing technology company Brevo exposed their data and enabled hackers to send hundreds of thousands of phishing emails.
Trezor said in a blog post that hackers exploited the breach at Brevo, which it uses to distribute newsletters, to send about 347,000 phishing emails to its customers.
The emails contained malicious links that purported to come from Trezor. When clicked, the links downloaded an application that asked users to provide their wallet backup password.
One of the phishing emails carried the subject line, “Critical Security Alert: STM32 Entropy Vulnerability.”
Trezor warned that anyone who provides their wallet backup password to attackers could have their cryptocurrency stolen irreversibly through the public blockchain.
Brevo said in an incident status update that hackers gained access to 138 customer accounts, which were then used to distribute the phishing messages at scale.
The company said the attackers exploited a flaw that resulted in their access being “not properly scoped”, allowing them to reach organisations that the compromised accounts could access.
Trezor said its own products, hardware wallets and account systems were not affected by the incident.
The breach highlights the cybersecurity risks companies face through third-party service providers that handle customer data or support business operations.
It is the second security incident involving Trezor in recent weeks. In August, the company warned customers that a breach at its shipping partner, ShipMonk, had exposed the names, phone numbers, email addresses and postal addresses of at least 81,000 people who had purchased and received Trezor hardware wallets.
