A breach at email provider Brevo led to convincing scam emails sent to some crypto customers. Check urgent warnings through the company’s official app or website, not through an email link.
In 60 seconds
- Trezor, CoinTracking, and BitBox subscribers were among those targeted by convincing scam emails.
- Open the company’s official app or type its website address yourself before acting on an urgent warning.
- Do not install an app or enter a wallet recovery phrase through an unsolicited email.
- If you entered a Trezor wallet backup, Trezor advises moving funds to a new wallet.
Who should care
People subscribed to newsletters from Trezor, CoinTracking, or BitBox should treat unexpected security emails with care. Trezor makes hardware wallets, which store cryptocurrency private keys offline. CoinTracking customers were among those reported to have received a phishing email. BitBox was also named in the report.
Other newsletter subscribers may be at risk too. Brevo, the email marketing provider involved, first said an attacker accessed 120 customer accounts. Brevo later reported that 138 accounts had been accessed. Six were used to send phishing emails, and contact lists were exported from 43 accounts. The number of people who acted on the messages is not known.
What the messages asked people to do
Phishing is a scam message designed to trick someone into clicking a link, installing software, or sharing private information. Malwarebytes said the messages came from legitimate company domains and looked convincing.
One message sent to Trezor subscribers claimed there was a serious hardware problem. It urged recipients to download an app and enter their wallet backup. Another message sent to CoinTracking customers claimed they needed to refresh their API keys through a malicious link. An API key is a code that lets one service connect to another.
The reported Trezor hardware claim was part of the phishing message. Malwarebytes did not report it as a confirmed Trezor defect. The report also says some recipients may have fallen for the messages, but it does not give a number.
How to check an urgent warning safely
Do not use an email link to investigate a message about an account or device problem. Open the company’s official app, or type a website address you already know into your browser. Look for a matching notice there. You can also contact the company through details listed on its official site.
Do not install an app from an unsolicited email, even if the message sounds urgent. Never enter a wallet recovery phrase anywhere except on your physical device. A recovery phrase is the set of words used to restore access to a crypto wallet. Malwarebytes says reputable companies will not ask for a recovery phrase, API key, or login details by email.
If you entered a Trezor wallet backup after following one of these messages, Trezor advises moving the funds to a new wallet. If you followed a similar link connected to another provider, contact that provider directly for advice.
Does this affect me?
- Who may be affected
- Crypto users subscribed to Trezor, CoinTracking, or BitBox newsletters should care first. Other Brevo customers and their subscribers may also receive targeted messages.
- How to check
- Open the provider’s official app or type its website address yourself. Look for the same security notice there instead of using the email link.
- What to do
- If the message is unexpected, check it through the official site and contact the provider there if you clicked or entered information.
- What to avoid
- Do not install apps from unsolicited email links or enter a wallet recovery phrase, API key, or login details in response to an email.
Common questions
How can I tell whether a security email is real?
Do not rely on the sender address or the message’s appearance. Open the company’s official app or type its website address yourself and check for the same notice. Contact the company using details from that site.
What should I do if I entered my Trezor wallet backup?
Trezor advises moving the funds to a new wallet. Do not enter the backup again on a website or app reached through an email. If the message involved another provider, contact that provider directly for advice.
Does this report confirm that Trezor hardware has a security defect?
No. The reported Trezor message made that claim, but Malwarebytes described it as part of a phishing campaign. The report did not identify the claimed hardware problem as a confirmed defect.
Primary source
This article is based on Malwarebytes, “Crypto customers targeted by scammers after email marketing provider breach,” published September 11, 2026: https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach. Visit the original for the full technical details. Read the complete original source.
Concerned this may affect your computer or account?
Bring the exact alert, device, product, and timeline. Leon will help separate urgent action from noise.
Article history: Published Sep 11, 2026 at 11:31 am EDT. Updates and corrections are noted here when material facts change.
