:

TREZOR: 347K USERS HIT BY PHISHING AFTER BREVO BREACH

SECURITY DESK1 MIN READ
FRI, SEP 11, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Cryptocurrency wallet provider Trezor revealed phishing attacks targeting 347,000 customer email addresses this week. The campaign resulted in 2,500 users clicking malicious links.

The attacks followed a breach of Brevo, an email marketing platform used by Trezor. Attackers leveraged the compromised email list to distribute phishing messages impersonating Trezor communications. Of the 347,000 targeted addresses, approximately 0.7% clicked embedded malicious links in the phishing emails. Trezor did not specify whether any wallets were compromised or funds stolen as a result of the successful clicks. Trezor advised users who clicked the links to check their wallets for unauthorized activity and reset passwords. The company recommended enabling additional security measures such as two-factor authentication. This incident highlights ongoing risks for cryptocurrency users, particularly those relying on third-party email services for communication. Trezor has not disclosed whether it plans to change email providers or implement additional security measures with Brevo.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Threat actors are exploiting trusted AI services to host malicious content and deceive users. Security firm Huntress has identified campaigns weaponizing AI platforms as attack vectors.

1H AGOAI Desk

A deceptive malware campaign called ClickFix is rapidly infecting both Windows PCs and Macs by exploiting user frustration with legitimate system issues.

2H AGOIndustry Desk

Researchers have identified ways that Claude users circumvented AI safety measures designed to prevent assistance with dangerous biological weapons research. The workarounds exploit the difficulty of distinguishing legitimate scientific inquiry from harmful applications.

2H AGOAI Desk

A US court has sentenced Ukrainian national Oleksii Lytvynenko to four years in prison for conspiracy to commit wire fraud linked to Conti ransomware attacks. Lytvynenko participated in the criminal scheme between 2021 and 2022.

3H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.