:

TREZOR: 347K USERS HIT BY PHISHING AFTER BREVO BREACH

SECURITY DESK1 MIN READ
FRI, SEP 11, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Cryptocurrency wallet provider Trezor revealed phishing attacks targeting 347,000 customer email addresses this week. The campaign resulted in 2,500 users clicking malicious links.

The attacks followed a breach of Brevo, an email marketing platform used by Trezor. Attackers leveraged the compromised email list to distribute phishing messages impersonating Trezor communications. Of the 347,000 targeted addresses, approximately 0.7% clicked embedded malicious links in the phishing emails. Trezor did not specify whether any wallets were compromised or funds stolen as a result of the successful clicks. Trezor advised users who clicked the links to check their wallets for unauthorized activity and reset passwords. The company recommended enabling additional security measures such as two-factor authentication. This incident highlights ongoing risks for cryptocurrency users, particularly those relying on third-party email services for communication. Trezor has not disclosed whether it plans to change email providers or implement additional security measures with Brevo.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A US court has sentenced Ukrainian national Oleksii Lytvynenko to four years in prison for conspiracy to commit wire fraud linked to Conti ransomware attacks. Lytvynenko participated in the criminal scheme between 2021 and 2022.

JUST NOWAI Desk

A new Android malware strain called Mantax Otax encrypts files, steals data, and harasses victims through spam and contact harassment. The hybrid threat represents a growing trend of multi-functional mobile malware.

JUST NOWSecurity Desk

GitLab has issued an urgent advisory for users to immediately patch a maximum-severity path traversal vulnerability (CVE-2026-85706). The flaw requires immediate action to prevent potential exploitation.

1H AGOIndustry Desk

Japan's Digital Agency confirmed unauthorized access to its servers, with personal data on approximately 246,000 individuals potentially compromised. The breach marks a significant security incident for the government body overseeing the nation's digital transformation.

8H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.