← BACK TO FEED
TAG

trezor2 articles

Trezor Customers Hit by Phishing Wave After Marketing Platform Botches SSO Security

Trezor has warned approximately 347,000 customers that they received phishing emails after its third-party marketing platform, Brevo, was hacked via a SAML Single Sign-On (SSO) vulnerability that allowed an attacker to gain unauthorized access to multiple accounts. The phishing emails, titled "Critical Security Alert: STM32 Entropy Vulnerability," directed users to a malicious website where entering their wallet backup could result in lost funds; around 2,500 users clicked the link before the site was taken down within 20 minutes. This breach follows a separate recent incident in which Trezor's shipping provider ShipMonk exposed the personal data of tens of thousands of customers, raising concerns about an increased risk of targeted phishing attacks against Trezor users.

13 Sept 2026

Trezor's Shipping Partner Kept Data It Promised to Delete. 67,000 Customers Are Now Paying the Price.

Trezor has disclosed that a breach at its shipping provider ShipMonk exposed the personal data of 67,000 U.S. customers, including names, addresses, phone numbers, and order details from 2019–2021 — data Trezor had repeatedly been assured was deleted. The breach stemmed from a zero-day SQL injection vulnerability (CVE-2026-72898) in Metabase, with the ShinyHunters extortion gang reportedly responsible. While the hardware wallets themselves remain secure, Trezor has warned affected customers to be vigilant against phishing, scam calls, and social engineering attacks exploiting the leaked information.

6 Sept 2026