Back to blog
Hacks célèbressupply chainemail

Brevo Hacked: Trezor Phishing Sent from help@trezor.io, 347,000 Emails Targeted

Published on 2026-09-116 min readCleanIssue

> TL;DR: On September 9, 2026, Brevo — the French email marketing platform (formerly Sendinblue) — suffered a security incident affecting 120 customer accounts. An unauthorized actor accessed the sending system and used legitimate accounts, including Trezor's, to dispatch phishing emails. Trezor's opt-in newsletter database (347,000 addresses) was hit: recipients got a fake "critical security alert" from the genuine help@trezor.io address, citing a purported STM32 microcontroller vulnerability in cold wallets and pushing an application that asked for the wallet recovery seed. Trezor took the phishing domain down in 20 minutes; 2,500 users had already clicked.

What happened, precisely

The attack illustrates a shift in the control point: phishing no longer needs to spoof the sender. The emails left Trezor's actual Brevo account, from the real support address with valid domain authentication — every technical control your users and filters treat as proof of authenticity (SPF, DKIM, domain reputation) passed, because the message was genuinely sent by the legitimate company's legitimate platform.

The pretext was calibrated: a "microcontroller vulnerability" exposing seeds to brute-force, urgency framing, and a link to an app requesting the recovery phrase — the one secret whose theft is irreversible in crypto.

Trezor's response deserves note: phishing domain cut in 20 minutes, impact limited to 2,500 clicks out of 347,000 messages, immediate suspension of the Brevo account, fast public disclosure. That is a well-executed phishing response playbook — it likely saved tens of millions in crypto.

The Trezor context: the third-party streak

This is the third Trezor incident via a vendor in under three years: support portal compromised in January 2024 (66,000 users), then ShipMonk — its logistics provider — hacked in August 2026 via a Metabase SQL injection zero-day (81,000 customers ultimately affected across the US, Brazil, Colombia, Italy, Portugal, Sweden, and the UK, with ShinyHunters extortion on top). No internal Trezor system was compromised in any of these — yet customer data leaks regularly.

Why this matters to you

Brevo is a French company, one of the most widely used transactional email providers among French SaaS and e-commerce — often for exactly Trezor's use cases: newsletters, security alerts, account emails. The structural lesson: the perceived security of your emails (your brand, your security alerts, your password-reset flows) depends on your ESP. An attacker who compromises a SaaS vendor's ESP account can send a fake payslip notice or a fake reset link from the vendor's legitimate address — to your employees or theirs.

What to do

  • Inventory your ESPs and sending providers: who can send email from your domains today, with which DKIM keys, and what data perimeter (lists, segments) each vendor holds.
  • Segment audiences: a newsletter base (347,000 opt-ins) should not cohabit with critical transactional email. Separate accounts, separate sending domains where possible.
  • Prepare a phishing response plan measured in minutes: Trezor's 20-minute takedown is the product of a rehearsed exercise. Who in your company can get a domain pulled, revoke a sending key, and alert users within the hour?
  • Educate on secret requests: no legitimate security alert ever asks for a seed, password, or MFA code by email. That simple message, repeated, is the last barrier when all others have fallen.
  • Contractually frame ESPs: incident notification deadlines, minimal data perimeter, accountability along the sending chain.
  • The broader lesson

    This case confirms 2026's defining pattern: attackers stop breaching front-line defenses and borrow legitimate channels instead — an email provider, a logistics firm, a support portal. Your attack surface includes your vendors' ability to send messages in your name. Auditing it is part of auditing your own product.

    Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Related articles

    Three adjacent analyses to keep exploring the same attack surface.

    Sources

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit