Trezor took the phishing domain down within 20 minutes, holding the click count at 2,500 of the 347,000 recipients.

 

What happened

An unauthorized actor reached Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, and used it to send emails from customer accounts, including Trezor's, the company stated following the September 9, 2026 incident. The phishing attempt reached roughly 347,000 email addresses from Trezor's opt-in newsletter database. Messages arrived as critical security alerts from help@trezor.io, claiming a hardware vulnerability in the company's wallets could expose customer recovery data, and directed recipients to download an application that requested their wallet backup, BleepingComputer reported. Trezor removed the phishing domain within 20 minutes, which limited the campaign to 2,500 people who clicked before the takedown. No other Trezor system was involved.

 

Going deeper

Every authentication check passed because the messages were genuinely sent through the platform Trezor authorized. SPF, DKIM, and DMARC records confirm that a sending server has permission to send for a domain, and a platform holding that permission on the organization's behalf passes those checks, whoever is operating it. Recipients saw the real sender address, correct branding, and a message arriving through the channel they had opted into. The lure itself was built for the audience, since a warning about a flaw in the hardware wallet a recipient owns produces exactly the urgency that overrides caution. Nothing in the message required the attacker to imitate anything.

 

What was said

An unauthorized actor "gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's," the company said in its incident notice, confirming the platform incident affected 120 Brevo accounts. Trezor added that the exposed addresses might be used in further phishing attempts and that it had suspended its Brevo account to stop additional distribution.

 

In the know

Three separate Trezor incidents in under two years have originated at third parties rather than at Trezor itself. Its support ticketing portal was compromised in January 2024, exposing names, usernames, and email addresses for roughly 66,000 users. Its logistics and shipping provider was breached in 2026 through a Metabase SQL injection zero-day, with the count rising from an initial 14,000 to 81,000 customers as the investigation continued, according to BleepingComputer, which also learned the shipping provider received extortion emails from the ShinyHunters gang. The pattern across all three is that the organization's own systems held, while the services around it did not.

 

The big picture

Healthcare organizations often run patient newsletters, appointment reminders, wellness campaigns, and portal notifications through the same type of platform. A vendor sending communications on behalf of a covered entity that involves protected health information is a business associate, and the Privacy Rule requires written assurances that it will safeguard the information, with the covered entity prohibited from authorizing any use that would violate the rule, under HHS requirements. Those agreements rarely address the scenario here, where the platform is not breached in the sense of losing data but is used to send from the client's identity. Organizations should establish which marketing and communication platforms can send using their domain, whether those accounts require phishing-resistant authentication, and how quickly the organization could suspend an account and take down a malicious domain. Trezor's twenty-minute takedown is the reason 344,500 recipients did not click.

 

FAQs

Does DMARC prevent this kind of attack?

No. Authentication records confirm that a sending platform is authorized to send for a domain, which remains true when an attacker operates that platform. The controls work as designed, and the assumption underneath them, that an authorized sender is a trustworthy one, is what fails.

 

Is an email marketing platform a business associate?

Where it creates, receives, maintains, or transmits protected health information on behalf of a covered entity, yes, and a written agreement is required. A platform sending appointment reminders or clinical communications meets that definition even when the message content seems routine.

 

What should an organization do when its sending platform is compromised?

Suspend the account to halt further distribution, identify and take down any domain used in the campaign, notify recipients through a channel the attacker does not control, and determine which address lists were exposed for use in later attempts.

 

Why does the exposed address list matter after the campaign ends?

An attacker holding a verified list of an organization's subscribers can target the same people again from other infrastructure, knowing they have an existing relationship with that brand. The list retains value long after the original messages are blocked.

 

How can staff verify a security alert appearing to come from their own organization?

By reaching the organization through a known route rather than the message, meaning a bookmarked portal, a published phone number, or an internal channel. Alerts genuinely requiring action are reachable through those routes, and alerts that exist only in the email are the ones worth doubting.