Brevo Hacked: Trezor Phishing Sent from help@trezor.io, 347,000 Emails Targeted
> TL;DR: On September 9, 2026, Brevo — the French email marketing platform (formerly Sendinblue) — suffered a security incident affecting 120 customer accounts. An unauthorized actor accessed the sending system and used legitimate accounts, including Trezor's, to dispatch phishing emails. Trezor's opt-in newsletter database (347,000 addresses) was hit: recipients got a fake "critical security alert" from the genuine help@trezor.io address, citing a purported STM32 microcontroller vulnerability in cold wallets and pushing an application that asked for the wallet recovery seed. Trezor took the phishing domain down in 20 minutes; 2,500 users had already clicked.
What happened, precisely
The attack illustrates a shift in the control point: phishing no longer needs to spoof the sender. The emails left Trezor's actual Brevo account, from the real support address with valid domain authentication — every technical control your users and filters treat as proof of authenticity (SPF, DKIM, domain reputation) passed, because the message was genuinely sent by the legitimate company's legitimate platform.
The pretext was calibrated: a "microcontroller vulnerability" exposing seeds to brute-force, urgency framing, and a link to an app requesting the recovery phrase — the one secret whose theft is irreversible in crypto.
Trezor's response deserves note: phishing domain cut in 20 minutes, impact limited to 2,500 clicks out of 347,000 messages, immediate suspension of the Brevo account, fast public disclosure. That is a well-executed phishing response playbook — it likely saved tens of millions in crypto.
The Trezor context: the third-party streak
This is the third Trezor incident via a vendor in under three years: support portal compromised in January 2024 (66,000 users), then ShipMonk — its logistics provider — hacked in August 2026 via a Metabase SQL injection zero-day (81,000 customers ultimately affected across the US, Brazil, Colombia, Italy, Portugal, Sweden, and the UK, with ShinyHunters extortion on top). No internal Trezor system was compromised in any of these — yet customer data leaks regularly.
Why this matters to you
Brevo is a French company, one of the most widely used transactional email providers among French SaaS and e-commerce — often for exactly Trezor's use cases: newsletters, security alerts, account emails. The structural lesson: the perceived security of your emails (your brand, your security alerts, your password-reset flows) depends on your ESP. An attacker who compromises a SaaS vendor's ESP account can send a fake payslip notice or a fake reset link from the vendor's legitimate address — to your employees or theirs.
What to do
The broader lesson
This case confirms 2026's defining pattern: attackers stop breaching front-line defenses and borrow legitimate channels instead — an email provider, a logistics firm, a support portal. Your attack surface includes your vendors' ability to send messages in your name. Auditing it is part of auditing your own product.
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Liquid Network: 4,000 BTC Stolen via Elements Bug, 3,400 Returned After On-Chain Negotiation
On September 6, 2026, nearly 4,000 BTC (about $320 million, 95% of reserves) left the Liquid federation wallet via SideSwap's Peg-out Authorization Key, after L-BTC was created exploiting a bug in the Elements software. 3,400 BTC were returned the next day after signed on-chain exchanges; 598.5 BTC ($47M) remain held.
Revolut: Passports, KYC Selfies, and Bitcoin History Handed to an Attacker Impersonating a Government Agency
Revolut (80+ million customers) has notified a data breach: an attacker requested personal data by email from a government agency's domain, with valid domain authentication credentials. Copies of passports, facial verification selfies, IBAN statements, and complete transaction history (including Bitcoin) were disclosed. Suspected targeting of high-net-worth users per ZachXBT.
Florida DAVID Database: 200,000 Driver Records Claimed by ShinyHunters via a Police Account
Florida's DMV (FLHSMV) confirms a breach of the DAVID driver database discovered September 4, 2026. Official version: credentials of a Plant City Police Department user improperly stored on a personal device. ShinyHunters' version (200,000+ records claimed): a password reset flaw granting access to DMV and FBI accounts.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.