Trezor confirmed in a blog post this week that an attack on Brevo, a marketing technology company it uses to send newsletters, enabled hackers to send a large volume of phishing emails to customers. The emails carried a malicious link that, when opened, downloads an app asking for the victim's wallet backup password. One subject line read: "Critical Security Alert: STM32 Entropy Vulnerability." If obtained, the password can be used to irreversibly steal the customer's cryptocurrency funds on the public blockchain.
Brevo stated in an incident report that hackers accessed 138 accounts to send the phishing messages, abusing a flaw that caused their access "not to be properly scoped," resulting in permissions being "wrongly granted" to all reachable organisations. Trezor emphasised that none of its products, wallets, or accout system were directly affected.
This follows a data breach in August at Trezor's shipping partner ShipMonk, which exposed the names, phone numbers, email addresses, and postal addresses of at least 81,000 people who purchased Trezor hardware. Since then, some individuals have received physical letters claiming to be from Trezor, containing a QR code that leads to a fake page designed to steal wallet passwords. The combination of exposed personal data and crypto ownership puts victims at risk of targeted violence, including so-called "wrench attacks" where attackers use physical force to extract passwords.
Trezor said it is reevaluting its relationships with vendors and warned customers that their email addresses may be used again in future phishing attempts.