Trezor phishing emails: the sender looked right. The request wasn’t.
Trezor says a September 9 incident at email provider Brevo was used to send phishing messages to its newsletter audience. The malicious app requested wallet backups; Trezor says its wallet systems were not breached.
Source and context ↗What did Trezor confirm?
In its September 10 notice, Trezor said about 347,000 newsletter addresses were affected. The message claimed a security vulnerability and linked to a download. Trezor suspended the provider account and warned that the addresses might be reused for phishing. It could not confirm whether the list had been exported. Read Trezor’s incident notice.
Why “check the sender” is only the beginning
A familiar sender is one clue. It cannot carry the entire security decision. The next question is what the message asks you to do. Does it turn a supposed emergency into a request for a secret? Does it move you from an app you know into a download you have never used?
Think of this as two doors. The first door is the communication channel: where the message arrived. The second is the authority to take an action: whether the request makes sense and has been independently verified. Getting through the first door should not automatically open the second.
A security-sounding subject line does not make a request for a secret legitimate.
A checklist for the next security email
- Stop before installing anything. An unexpected warning should trigger verification, not an automatic download.
- Open the official app or site independently. Look for a matching notice there. The FTC recommends using a known contact route to verify suspicious messages. FTC guidance.
- Keep your backup out of emailed forms. Trezor says it will never contact you asking for that backup.
- If you entered it, use the official response instructions immediately. Trezor directs affected users to move funds to a new wallet. Follow the guidance linked from its incident notice, not a helper arriving in your DMs.
What should readers distinguish?
Is an email-provider incident the same as a hardware-wallet exploit?
No. These are different failure points. A newsletter, a device, and a wallet backup should not be treated as interchangeable just because the same company name appears beside them.
Does reading this story tell me whether my wallet is compromised?
No. Your own actions matter. Write down whether you only received a message, followed it, installed something, or entered sensitive information. Those are different situations to explain to official support.
What is the useful long-term habit?
Decide how you will verify an emergency before an emergency arrives. Bookmark the support route, know where official notices appear, and treat surprise urgency as a reason to slow down.
Next: nine checks before trusting a website, and why knowing your details does not authenticate a caller.
Sources and reporting notes
Source review: September 12, 2026. AI-assisted synthesis of linked reporting and public statements, with our own explanatory examples. We have not independently examined affected accounts, devices, or private incident records.
- Source 1: trezor.io — security incident at brevo our third party email provider
- Source 2: consumer.ftc.gov — how recognize avoid phishing scams
See our editorial policy. Send corrections to hello@richretards.com.