At a glance
- What changed
- Newsletter channel compromised.
- Who it affects
- Affected email subscribers.
- When
- September 17 scope update.
Trezor partner offer and conditions ↓

Trezor reports an incident at its email provider
Trezor said an attacker used its Brevo marketing account to send a phishing email on September 9. Its September 17 update reported that 347,149 newsletter contacts had been exported. Trezor says its wallet and product systems were not affected. These are the company’s reported findings: exposure of contact data and misuse of an email channel, not independently established theft from every recipient’s wallet.
[1]A disclosed backup is a different problem
Trezor’s separate emergency guide treats a suspected exposed wallet backup as urgent and advises moving funds to a wallet created with a new backup. It provides different procedures depending on whether another device is available. The guide warns that performing the process with only one device is relatively complicated.
That distinction matters here. Receiving a fraudulent email is not the same event as entering recovery words into a malicious application. If a person did disclose those words, they should use Trezor’s official incident guidance and the device-appropriate emergency procedure. This article is not a substitute for that sequence, and it does not recommend wiping a device before the person has established how to retain access and complete the transfer.
[2]Reconstruct what happened without sharing secrets
For an illustrative incident report, imagine that a subscriber received the message, opened it and then closed it. Another subscriber followed the link and installed the offered application. A third entered wallet backup words into it. Those are three different histories, and a useful support request should describe the actual one.
A short record can include the approximate time, the email subject, whether a link was opened, whether software was downloaded and whether any sensitive information was entered. It should never include the backup words themselves. This gives the legitimate support team facts to work with while avoiding another disclosure during the attempt to get help.
The exercise is not a guarantee that a particular computer is clean or that opening any link is harmless. It is a way to avoid collapsing several different actions into the vague statement “I was hacked.” That phrase can obscure both the urgency of a disclosed secret and the limited evidence in a case where the person only received an email.
Why an authentic-looking email can still be dangerous
Our reading is that this incident is especially instructive because the message arrived through a channel subscribers associated with the company. A familiar sender name, branding or conversation history can make an instruction feel expected. The useful question is whether the requested action makes sense, not merely whether the message looks polished.
Consider a fictional follow-up claiming that a reader must install a recovery tool before a deadline. The urgency can push the reader to act before checking the announcement through a route they choose independently. A safer verification method is to open the known official site or app directly and look for the same notice there. This is a general method for checking the message’s claim; it is not a statement that we observed another campaign after the reported incident.
Someone helping a family member can ask them to describe what the message requested rather than forwarding sensitive screenshots or entering information on their behalf. That keeps the investigation focused on the instruction and the person’s actual actions.
Read the update as a dated account of the evidence
The original announcement and later contact-export figure describe different stages of the company’s investigation. A careful reader should keep those dates attached to the statements. A later number can refine the scope of a data exposure without proving that every affected person followed the malicious instruction or suffered a financial loss.
For a subscriber who did not disclose a backup, the practical issue is evaluating future messages with the incident in mind. For a subscriber who did, the urgent issue is following the official recovery response. Those paths should not be merged into a blanket instruction for everyone to move funds. Clear reporting names what was exposed, what action the recipient took and whose conclusion is being relied on. That is how this security story can help readers respond proportionately without understating a real secret-disclosure emergency.
Dates to know
As announced by the provider. A listed date does not confirm current availability or eligibility.
- Updated notice confirms exported contact countDate passed[1]
Respond to a suspicious Trezor email
Select what happened to identify the relevant next step.
- Received the email
Check the official notice
Do not follow the message’s download or backup request.
- Entered a backup
Follow the urgent recovery advice
Trezor instructs affected users to move funds to a new wallet.
Based on the official announcement; availability may change. [1]
- 347,149 contacts exported.
- Vendor reports unaffected wallets.
- Backup disclosure is urgent.
Official sources & further reading
Independently written from the primary sources below. Checked on 26 September 2026.
- Security incident at Brevo, our third-party email provider ↗Announcement · 10 September 2026
- Move crypto to a wallet with a new wallet backup ↗Documentation
Open-source hardware wallets
No public discount code is attached. Any store promotion has its own terms.
Permanent partner link. Campaign dates and benefits are separate.
We may earn a commission, at no extra cost to you. Account and country conditions apply.