Brevo-abused Trezor security-alert phishing campaign
Campaign
Summary
Hide ▲
Show ▼
A Brevo-abused phishing campaign targeted Trezor newsletter subscribers with fake security-alert emails, reaching 347,000 email addresses and driving 2,500 clicks before takedown.
Related Happenings
ShipMonk hit by network compromise
Incident
H score43
First: 13.08.2026 18:13
Last: 13.08.2026 18:13
Sources 1
About this happening:
Trezor says an August ShipMonk breach now affects 81,000 customers after an additional 67,000 U.S. customers were exposed when ShipMonk did not delete customer dat...
ShipMonk hit by network compromise
IncidentAbout this happening: Trezor says an August ShipMonk breach now affects 81,000 customers after an additional 67,000 U.S. customers were exposed when ShipMonk did not delete customer dat...
Trezor customers customer data exposed after ShipMonk breach
Data Leak
H score44
First: 13.08.2026 18:13
Last: 13.08.2026 18:13
Sources 1
About this happening:
A ShipMonk breach exposed Trezor customer order data for 11,742 fully exposed records and 1,947 partially exposed records, increasing the risk of phishing and impe...
Trezor customers customer data exposed after ShipMonk breach
Data LeakAbout this happening: A ShipMonk breach exposed Trezor customer order data for 11,742 fully exposed records and 1,947 partially exposed records, increasing the risk of phishing and impe...
Latest development: 05.09.2026 17:17
Trezor said another 67,000 U.S. customers were impacted in a breach at its shipping provider ShipMonk, with exposed information including customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The exposure adds to earlier customer records already disclosed and does not affect the security of Trezor hardware wallets.
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Latest development: 05.08.2026 14:43
Kali365 uses device-code phishing to target US organizations, presenting lures that impersonate SharePoint, OneDrive, or DocuSign before redirecting victims to Microsoft's legitimate device login portal for attacker-provided codes; successful approvals can yield access and refresh tokens with continued access to Microsoft 365 email, documents, and cloud resources, and ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week.
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
Timeline
-
11.09.2026 10:55 1 articles · 1h ago
Brevo account compromise enables phishing email abuse
Initial DisclosureBrevo suffered a security incident on September 9, 2026 after an unauthorized actor gained access to its system and used various customer accounts, including Trezor's newsletter account, to send emails. The incident affected 120 Brevo accounts.
Show sources
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach — www.bleepingcomputer.com — 11.09.2026 10:55
-
11.09.2026 10:55 2 articles · 1h ago
Trezor newsletter subscribers hit by fake security-alert phishing emails
Campaign Scope UpdateTrezor customers who opted in to newsletters received fake "critical security alert" emails from [email protected] claiming that a "hardware microcontroller vulnerability" in Trezor cold storage wallets' STM32 microcontrollers could expose their seeds to brute-force cracking. The phishing campaign targeted 347,000 email addresses, affected 2,500 users who clicked the malicious link, and the domain used in the attacks was taken down within 20 minutes; Trezor also suspended the Brevo account to stop further email distribution.
Show sources
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach — www.bleepingcomputer.com — 11.09.2026 10:55
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach — www.bleepingcomputer.com — 11.09.2026 10:55