Trezor says phishing emails sent to its customers earlier this week were made possible by a Brevo login flaw. According to Trezor, the campaign targets 347,000 email addresses associated with Trezor subscribers, treating the addresses as potentially reusable for further phishing.
Trezor reports that 2,500 users clicked an embedded malicious link in the emails. Bleeping Computer also reports that Trezor has characterized the incident as beginning after the Brevo breach and that the company is investigating the impact on affected recipients. Cointelegraph similarly focuses on the number of targeted subscribers and the company’s assessment of how the attacker may reuse known addresses.
While the outlets differ slightly in emphasis—Cointelegraph highlights the “known to the attacker” framing and Bleeping Computer underscores the click-through impact—both describe the same figures: 347,000 targeted email addresses and 2,500 users who clicked the malicious link. Both also present the event as an email-delivery compromise tied to Brevo credentials rather than a direct compromise of Trezor hardware systems.