ProBackend
social engineering phishing
2 hours ago5 min read

Understanding Modern Cybersecurity Data Breaches: How the Trezor Phishing Campaign Exposed 347,000 Users Through Third-Party Vendor Brevo

Comprehensive expansion of the Trezor phishing and Brevo supply-chain compromise article, analyzing the 347,000 targeted addresses, 2,500 clicks, ClickFix scripts, WordPress backdoors, and broader cybersecurity data breaches lessons.

When hardware cryptocurrency wallet manufacturer Trezor revealed in September 2026 that a phishing campaign had targeted 347,000 of its customer email addresses—resulting in 2,500 users clicking malicious links—it served as another stark reminder of the fragile state of supply-chain security. In an era where organizations invest heavily in perimeter defenses, recent cybersecurity data breaches consistently demonstrate that attackers bypass direct enterprise fortifications by exploiting third-party service providers.

This multi-layered incident involving Trezor, its marketing platform Brevo, and subsequent edge-script injections illustrates the cascading risks inherent in modern digital ecosystems, offering critical lessons for risk management and incident response across industries.

The breach originated not within Trezor's core infrastructure, but at Brevo (formerly Sendinblue), a third-party customer relationship management and digital marketing platform utilized by Trezor for newsletter campaigns. According to disclosures from both companies, unauthorized threat actors gained access to Brevo's systems, compromising roughly 120 Brevo accounts, including Trezor's marketing account.

The attackers leveraged this access to send fraudulent emails directly to Trezor's opt-in newsletter database, encompassing approximately 347,000 email addresses. By utilizing a legitimate email infrastructure provider, the phishing messages successfully bypassed standard domain-reputation checks and spam filters that might have otherwise flagged messages originating from unknown external domains.

Crafting the Lure: Fake Hardware Vulnerabilities and Social Engineering

The precision of the phishing emails underscored how sophisticated threat actors leverage domain-specific knowledge in social engineering campaigns. Recipients received alarming "critical security alert" notices purporting to come from [email protected].

The emails claimed that a catastrophic "hardware microcontroller vulnerability" affected the STM32 microcontrollers inside Trezor cold storage devices, theoretically exposing user seed phrases to brute-force extraction. For cryptocurrency holders who prioritize cold storage specifically to insulate their digital assets from online threats, an alert threatening the physical integrity of their device represents a high-urgency hook.

The message urged recipients to click an embedded link to download a supposed emergency verification application designed to secure their funds. In reality, the link directed users to a malicious domain engineered to harvest recovery seeds or deploy info-stealing malware. Thanks to rapid detection, Trezor successfully disabled the malicious domain within 20 minutes of discovery, capping the number of affected users who clicked the link at approximately 2,500 individuals.

Broader Anatomy of Third-Party Cybersecurity Data Breaches

To understand how modern cybersecurity data breaches propagate, security analysts must examine the compounding nature of supply chain compromises. Just days after the initial newsletter intrusion, Brevo suffered an even broader supply chain attack when threat actors stole a long-lived Cloudflare API key with full account permissions that had been hardcoded into application source code.

This stolen credential enabled attackers to create a malicious Cloudflare Worker that modified content at the Content Delivery Network (CDN) edge for over five hours. The Worker altered web pages across Brevo domains and injected malicious JavaScript into embedded widgets, forms, and SDK loaders utilized by thousands of customer websites worldwide.

Security firm Sansec estimated that up to 100,000 websites embedding Brevo components were impacted. Visitors to these sites were greeted by fake Cloudflare verification pages instructing them to execute malicious PowerShell commands—a hallmark of the "ClickFix" social engineering technique. Furthermore, on WordPress sites embedding affected Brevo widgets, the injected scripts checked whether visitors were logged in as administrators and attempted to upload a persistent backdoor disguised as a fake plugin named "Web Media Optimizer" (wm.zip). This malicious plugin operated as an invisible backdoor, maintaining administrative session access and continuously injecting further ClickFix payloads.

Trezor’s Wider Vulnerability Pattern

The September 2026 phishing campaign is part of a troubling sequence of third-party exposure incidents faced by Trezor over recent years:

  1. January 2024 Support Portal Breach: Attackers compromised Trezor's third-party customer support ticketing portal, accessing names, usernames, and email addresses of roughly 66,000 users.
  2. August 2026 ShipMonk Logistics Breach: Threat actors exploited a critical Metabase SQL injection zero-day vulnerability in ShipMonk—Trezor's logistics and shipping partner—stealing customer order data initially reported as affecting 14,000 customers, but later revised upward to over 81,000 individuals globally after extortion threats by the ShinyHunters gang.
  3. September 2026 Brevo Email & Edge Breach: The marketing and newsletter infrastructure breach exposing 347,000 email addresses and triggering targeted phishing.

This pattern demonstrates that even when hardware manufacturers maintain rigorous control over firmware development and secure hardware enclave design, their customers remain vulnerable to upstream vendor compromises.

Strategic Defense and Governance Lessons

Mitigating risks stemming from third-party ecosystems requires organizations to move beyond traditional compliance questionnaires toward rigorous technical verification:

  • Zero-Trust API Management: Hardcoded API keys with broad administrative privileges—such as the Cloudflare credential compromised at Brevo—represent catastrophic single points of failure. Organizations must enforce automated secrets scanning, short-lived token generation, and strict principle-of-least-privilege scoping.
  • Edge Integrity Monitoring: Because edge-workers and CDN-level modifications rewrite content before it reaches traditional origin integrity checks, security teams must deploy client-side monitoring and Subresource Integrity (SRI) hashes for all embedded third-party scripts, widgets, and SDKs.
  • Customer Communication Resilience: Hardware vendors must establish verified out-of-band communication channels. Training users to recognize that legitimate device manufacturers will never ask for seed phrases or recovery words via email remains paramount, but technical hardening of email authentication (SPF, DKIM, DMARC) and rapid domain takedown capabilities are equally vital.

As enterprise reliance on SaaS platforms and third-party integrations deepens, safeguarding customer trust demands absolute vigilance across every tier of the supply chain.

the vendor was the weak link

More blogs