Phishing and scams

Trezor and Brevo: subscribers targeted by a fake security email

Following an incident at email provider Brevo, Trezor reports 347,149 exported addresses and a malicious email requesting wallet recovery words.

Conceptual illustration: Trezor and Brevo: subscribers targeted by a fake security email
Conceptual illustration · SecurCheck

What is confirmed

Trezor says the 9 September incident involved newsletter provider Brevo and that 347,149 marketing contacts were exported via its API.

An email from that channel promoted a fake app asking for wallet recovery words. Trezor says its products and wallets were not compromised.

What it means

An apparently credible sender is not enough: a compromised mailing provider can send through a normally legitimate channel.

The number of exported contacts is not the number of stolen wallets. Direct risk to funds depends in particular on whether recovery words were entered.

What to do

Do not use the email's links. Open the official app through a bookmark and review Trezor's published safety notices.

If you entered recovery words into a third-party app or website, follow Trezor's official instructions immediately to move assets to a new safe wallet.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Trezor — avis sur l’incident Brevo