BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Sep 10, 2026 · 3 min read · Original story

Multiple crypto companies warn customers of phishing emails after alleged provider breach

Multiple crypto companies warn customers of phishing emails after alleged provider breach
Multiple crypto companies warn customers of phishing emails after alleged provider breach

Editor's Note: Story updated 3:20 p.m. Eastern time with postmortem from Brevo.

Thousands of cryptocurrency holders were inundated with phishing emails on Wednesday after hackers breached an email provider and sent out corrupted messages.

Popular cryptocurrency companies Trezor, CoinTracking and BitBox confirmed that phishing emails were sent out to customers subscribed to their newsletters.

Trezor and BitBox did not confirm which email provider was breached but CoinTracking said email service provider Brevo was the source of the phishing emails.

BitBox noted that multiple other crypto companies targeted “all share the same newsletter provider.”

Brevo released its own notice on Thursday morning warning that an attacker had access to 120 customer accounts.

“The bad actor used the access to send phishing emails to the client's contactbase. The access has been closed,” the company said.

Brevo declined to answer a series of questions, instead sending Recorded Future News a postmortem published on Thursday afternoon. The company said 138 Brevo accounts were breached and six of those were used to send phishing emails to the contacts stored there.

The attackers exported contacts from 43 accounts. The company claims it has removed the hacker from the system.

Brevo provided a detailed technical explanation for how the hackers broke in, essentially describing an attack in which the intruders stole the login information of legitimate users and expanded their access through a vulnerability in the system.

The company said it has deployed a permanent fix for the exploited issue and plans to cooperate with authorities.

Brevo was founded in Paris as an email marketing firm in 2012, and raised more than $580 million in December to help expand to other parts of its customer relationship management business.

Security alert phishing

Each of the emails sent out used the legitimate company domains and purported to be focused on security issues requiring customer action.

People who received the emails said they were alarmed at how legitimate they looked, and several clicked on the links before being taken to phishing websites that were nearly identical to the legitimate platforms.

For Trezor customers, people received an email titled “Critical Security Alert: STM32 Entropy Vulnerability” that urged them to click a link and take specific actions to address alleged security issues.

Trezor, a hardware wallet manufacturer, released a message on social media saying their third-party email provider was breached and that the email did not come from them.

“Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain,” the company said.

Trezor, which recently suffered a different breach exposing the personal details of 81,000 customers, also posted a notice on its website about the fake email.

CoinTracking said hackers sent an email titled “Data Breach Notice: Please refresh API Keys as soon as possible” to its customers that contained a malicious link.

BitBox explained that it sent a phishing warning to all its newsletter subscribers, contacted the provider and reported the phishing domains.

“Most of the phishing links appear to have been taken down already. We are still actively investigating this situation and will update you once we know more,” BitBox said.

Multiple data breaches involving cryptocurrency companies like Trezor and others have raised concerns about the exposure of identifying information related to digital currency owners. During the takedown of a noted cryptocurrency theft ring, DOJ prosecutors noted that the criminals ranked targets using lists of cryptocurrency owners stolen from cryptocurrency companies.

After Trezor’s recent data breach involving its shipping and logistics provider, customers of the company reported getting malicious QR codes by postal mail.

Experts have also seen an increase in wrench attacks — where wealthy cryptocurrency owners have been targeted and attacked in real life.

The number of wrench attacks grew 33 percent year-over-year, according to blockchain security audit company CertiK. The losses have reached $124 million so far this year, compared with $10.5 million reported in the first half of 2025.

Two weeks ago, cryptocurrency investor Harry Chun Tak Yeh was found dead after falling from his luxury 30th floor apartment in Paraguay. Police found his door open and said his home ​​had been ransacked.

References in this story

  1. Trezor (@Trezor) on X x.com Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any…
  2. CoinTracking (@Coin_Tracking) on X x.com 🚨 Important Security Notice🚨 Our third-party email service provider Brevo has experienced a security breach. Please note that the email titled “Data Breach Notice: Please refresh API Keys as soon as possible” was not…
  3. BitBox (@BitBoxSwiss) on X x.com Our preliminary review of the phishing mail that was sent out to our newsletter subscribers about an hour ago found that it is very likely that our newsletter provider got compromised. Multiple other Bitcoin companies…
  4. Brevo (@brevo_official) on X x.com This morning we have closed a security incident that allowed an attacker to access 120 Brevo accounts. The majority of those have no suspicious activity. The bad actor used the access to send phishing emails to the…
  5. Attacker gained access to client accounts - Brevo Status status.brevo.com The issue has been resolved, and all affected services are now functioning normally. Thank you for your patience while we worked to address the issue.
  6. Sendinblue Rebrands as Brevo | Full CRM Suite for Growing Businesses www.brevo.com Sendinblue is now Brevo. Learn why the leading digital marketing platform rebranded to reflect its growth into a full CRM Suite for businesses of all sizes.
  7. Trezor data breach impact now reaches 81,000 customers www.bleepingcomputer.com Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers.
  8. SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted therecord.media The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.
  9. Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen therecord.media The company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability.
  10. Scammer behind $245 million crypto heist pleads guilty to RICO charges therecord.media Malone Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets.
  11. ple₿eian princess 🧡 (@ellethereal) on X x.com @Trezor What about this letter? I DK how they got my address as I have moved many times in the past few years. I got this and the email today.
  12. 'Wrench' attacks against crypto holders appear to be on the rise therecord.media There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.
  13. Investigan muerte de chino que cayó del piso 30 www.latribuna.com.py El cuerpo sin vida de un ciudadano chino apareció tendido en el suelo al pie del edificio Jade Park, uno de los complejos residenciales más altos de la zona del...
  14. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  15. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  16. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  17. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

Guides related to this story

← Back to all news