Data Breach
Supply Chain Breach: Over 340,000 Trezor Users Targeted via Brevo Compromise
Hardware wallet maker Trezor revealed that hundreds of thousands of users received targeted phishing emails following an intrusion into email marketing platform Brevo.
Anatomy of the Brevo Third-Party Intrusion
Hardware cryptocurrency wallet manufacturer Trezor has confirmed that approximately 347,000 customers were subjected to targeted phishing lures following an unauthorized intrusion into its third-party email service provider, Brevo. The attackers gained illicit administrative access to Brevo's marketing systems and systematically broadcasted deceptive communications impersonating trusted cryptocurrency brands, including Trezor, BitBox, and CoinTracking. The phishing campaign aimed to trick recipients into revealing private seed phrases or downloading rogue application updates designed to drain digital asset holdings.
This incident illustrates the substantial supply-chain risk posed by third-party Software-as-a-Service (SaaS) providers. Even when an organization's core internal infrastructure and cryptographic controls remain robust, downstream service providers with access to customer communication channels can become direct vectors for sophisticated adversary campaigns.
Mitigating SaaS and Third-Party Risks
To safeguard corporate reputation and customer data integrity against supply chain compromises, enterprises should adopt strict vendor risk management programs. Organizations must demand comprehensive audit trails, enforce multi-factor authentication (MFA) with phishing-resistant protocols across all vendor integration portals, and minimize customer personally identifiable information (PII) stored on third-party marketing services. Customer education regarding strict communication policies—such as explicitly stating that administrators will never request credentials, private keys, or seed phrases—serves as the final critical defense line.
แหล่งที่มา: SecurityWeek เผยแพร่ครั้งแรก: Fri, 11 Sep 2026 12:48:04 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: SecurityWeek
เผยแพร่ครั้งแรก: Fri, 11 Sep 2026 12:48:04 +0000
บทความต้นฉบับ: https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
