https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider Retrieved 2026-09-20T21:20:42.325Z Skip to contentProducts AppCoinsLearn & Support Search...Search for anything...Cart0Hardware walletsWhy you need oneTrezor Safe 7Trezor Safe 5Trezor Safe 3Compare walletsAll products & accessoriesSave with bundlesBackupSafeguard your wealth with Keep MetalEnglishČeština日本語DeutschEspañolFrançaisPortuguês (Brasil)中文(简体)Bahasa IndonesiaBack to Trezor BlogNewsSecurity incident at Brevo, our third-party email providerTrezor TeamSharing insights on crypto, security & self-custody3 mins readSep 10, 2026Updated September 17, 2026: Brevo has confirmed that 347,149 marketing email contacts were exported from our list through the API during this incident. While your Trezor remains secure, your email address could now be used in more targeted email phishing attempts. Please remain vigilant and remember that Trezor will never ask for your wallet backup.On September 9, 2026, Brevo, the third-party marketing platform Trezor uses for newsletter campaigns, suffered a security incident affecting 120 Brevo accounts. An unauthorized actor gained access to Brevo's system and used it to send emails from various customer accounts, including Trezor's. The incident affected our opt-in newsletter database, roughly 347,000 email addresses. These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched. We have suspended the Brevo account to stop further email distribution. The phishing email sent from our account contained a malicious link that prompted users to download an app that asked users to enter their wallet backup.The email subject line was: Critical Security Alert: STM32 Entropy Vulnerability Do not click on any link; doing so could result in a loss of funds.The initial email was sent to 347,000 customers, all of whom have been contacted to inform them of the risk. We took down the domain at the DNS level within 20 minutes, preventing the link from working for anyone else and limiting access to 2,500 people who had clicked it before we took it down. This is possible because Brevo routes all communication via our domain. The email-sending function was also disabled to prevent further phishing emails.Warning messaging has been added to Trezor.io, Trezor Suite, community and support channels, direct email notifications, and other channels.Important: If you receive a suspicious email from Trezor, please take the following steps: Do not click any links or provide any personal information. Delete the email from your inbox promptly. If you have entered your wallet backup in any form, especially through a link provided in such emails, immediately move your funds to a new wallet. If you have not entered your wallet backup anywhere other than on your Trezor device during recovery, your assets remain secure. Please be careful of any email claiming to be from Trezor. We will never contact you asking for your wallet backup. We’re truly sorry for any concern this may have caused you. Our team is actively handling the incident, and further updates will be provided as necessary.Your questions, answered (FAQs) Was Trezor itself hacked? No. This was a breach of Brevo, the third-party platform Trezor uses for newsletter emails. No Trezor product, wallet, or account system was affected. What data was exposed? 347,149 newsletter subscriber email addresses were exported during the breach. Brevo's system holds no passwords, wallet data, or other personal information. Affected users may see an increase in phishing emails. I clicked the link but didn't enter anything. Am I at risk? No. The risk only applies if you entered your wallet backup into the app or anywhere online. Clicking the link alone doesn't expose your funds. I entered my wallet backup after clicking the link. What do I do? Move your funds to a new wallet immediately. Why does Trezor use a third-party provider for newsletters instead of handling it in-house? Most companies at our scale use a dedicated email platform to send newsletters, it handles deliverability, unsubscribes, and list management in ways an in-house system usually can't match. We're reviewing our vendor relationships and security requirements in light of this incident.ShareTrezor TeamSharing insights on crypto, security & self-custodyArticles written by Trezor's team members. Join the Trezor Newsletter!Receive insider offers, product news, and crypto insights, straight to your inbox.Your e-mailSubscribeBy clicking Subscribe you agree that Trezor Company s.r.o. will use your email solely to send you its newsletter. You can unsubscribe anytime using the link in any email. To see how we handle your data, view Trezor’s Privacy Policy.You might also likeNewsClear Signing comes to Trezor (our flagship security feature of 2026)Henry WindleNewsWhat's the best way to buy a large amount of bitcoin?Henry Windlea part of SatoshiLabs GroupJoin our newsletterGet self-custody tips, insights, and product updates.ProductsProductsTrezor Safe 3Trezor Safe 5Trezor Safe 7Trezor KeepCompare walletsTrezor Suite appAll products & accessoriesAppCoinsLearnLearnSupported coinsBlogThird-party wallet appsPrivacy and SecurityAbout usSupportKnowledge BaseForumSystem statusAccessibilityReturnsOtherOtherFAQsTerms of UseRefer-A-Friend ProgramAffiliate ProgramReseller ProgramResellersGitHubPress & MediaCareersSecurity PortalCookies settings© 2014–2026 Trezor Company s.r.o. All rights reserved.Cookies