Executive Summary
In September 2026, cryptocurrency hardware wallet manufacturer Trezor disclosed a sophisticated phishing campaign targeting 347,000 users following a breach of their third-party email provider Brevo. Threat actors compromised Brevo's systems and sent convincing phishing emails claiming a critical hardware vulnerability in Trezor devices, tricking 2,500 users into clicking malicious links before the campaign was shut down within 20 minutes. This incident represents Trezor's third major security breach in recent years, following previous compromises of their support portal and shipping provider.
This attack demonstrates the evolving sophistication of supply chain targeting, where attackers compromise trusted third-party service providers to reach high-value cryptocurrency users with credible social engineering tactics.
Why This Matters Now
Cryptocurrency phishing attacks are surging as threat actors increasingly target third-party service providers to bypass direct security controls, exploiting the trust relationships between companies and their vendors to reach high-value targets with sophisticated social engineering campaigns.
Attack Path Analysis
Threat actors compromised Brevo's email platform and gained unauthorized access to 120 customer accounts including Trezor's newsletter database. They leveraged this access to send convincing phishing emails to 347,000 Trezor customers, impersonating official security alerts about hardware vulnerabilities. The campaign successfully tricked 2,500 users into clicking malicious links that led to fake applications designed to harvest wallet backup credentials. While the immediate impact was contained through rapid domain takedown, the stolen email database creates ongoing phishing risk for affected customers.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained unauthorized access to Brevo's email platform, compromising 120 customer accounts including Trezor's newsletter database containing 347,000 email addresses
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Exploit Public-Facing Application
Phishing for Information: Spearphishing Link
Phishing: Spearphishing Attachment
Acquire Infrastructure: Domains
Gather Victim Identity Information: Email Addresses
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Third-Party Service Provider Risk Management
Control ID: 12.10.4
NYDFS 23 NYCRR 500 – Third-Party Service Provider Security Policy
Control ID: 500.11
GDPR – Processor Security Obligations
Control ID: Article 28
DORA – ICT Third-Party Risk Monitoring
Control ID: Article 28
CISA ZTMM 2.0 – Third-Party Risk Management
Control ID: 4.2
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
High-value targets for phishing campaigns exploiting cryptocurrency wallet vulnerabilities, requiring enhanced egress security and threat detection against sophisticated social engineering attacks.
Computer/Network Security
Direct sector impact from hardware wallet security incidents, necessitating zero trust segmentation and multicloud visibility to protect client cryptocurrency assets and infrastructure.
Investment Banking/Venture
Cryptocurrency investment portfolios vulnerable to phishing attacks targeting cold storage wallets, requiring encrypted traffic monitoring and anomaly detection for digital asset protection.
Technology/IT
Third-party email provider breaches expose client databases to phishing campaigns, demanding cloud firewall protection and inline IPS to prevent data exfiltration attacks.
Sources
- Trezor: 347,000 users targeted in phishing attacks after Brevo breachhttps://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/Verified
- Security incident at Brevo, our third-party email providerhttps://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-providerVerified
- Brevo System Status - Security Incidenthttps://status.brevo.com/incidents/pawbvhq8/write-upVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained this email platform compromise through segmented access controls and egress restrictions. Zero Trust segmentation could have limited lateral movement within Brevo's infrastructure and reduced the blast radius affecting multiple customer accounts.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native security fabric would likely have constrained the initial compromise scope by limiting unauthorized access pathways to the email platform infrastructure through identity-aware access controls
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have limited the attacker's ability to escalate privileges across customer account boundaries by enforcing strict identity-based access controls between tenant environments
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have constrained lateral movement between customer account segments by enforcing micro-segmentation policies within the email platform infrastructure
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have provided early detection of suspicious outbound communications to newly established malicious domains from the compromised email infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained large-scale data exfiltration by blocking or alerting on bulk email database transfers to unauthorized external destinations
Even with constrained infrastructure access and reduced exfiltration scope, some customer exposure would likely remain due to successful social engineering of end users
Impact at a Glance
Affected Business Functions
- Customer Communications
- Marketing Operations
- Customer Support
- Brand Reputation Management
Estimated downtime: 1 days
Estimated loss: N/A
Email addresses of approximately 347,000 Trezor newsletter subscribers were exposed through the Brevo breach. 2,500 users clicked on malicious phishing links attempting to steal wallet backup credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation for third-party email providers to limit blast radius of supplier breaches
- • Deploy egress security controls with FQDN filtering to block access to newly registered phishing domains
- • Enable multicloud visibility and anomaly detection to identify suspicious email sending patterns from legitimate platforms
- • Establish threat detection capabilities with real-time alerting for domain spoofing and brand impersonation attempts
- • Enforce encrypted traffic inspection and inline IPS to detect and block phishing payload delivery mechanisms



