Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, News

Trezor’s Vendor Breach Exposes 347,000 Users to Phishing — A Lesson in Third-Party Risk

What Happened

On September 9, 2026, an attacker breached Brevo, a third-party email marketing platform used by hardware wallet maker Trezor to send customer newsletters. The attacker exploited how Brevo handles SAML single sign-on to gain access to 138 customer accounts, including Trezor’s, then sent phishing emails from Trezor’s own account. The message carried the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and linked to a malicious site pushing victims to enter their wallet backup phrase. Trezor detected the campaign and took down the phishing domain within 20 minutes, but not before it reached roughly 347,000 email addresses and collected clicks from 2,500 recipients. Trezor suspended its Brevo account and confirmed no other company system was touched. Read the original report from SecurityWeek.

Why This Matters for Canadian Organizations

Trezor did not fail here. Its vendor did. Canadian organizations increasingly route customer communications through third-party marketing and CRM platforms, and each connection extends the attack surface beyond what internal security teams directly control. A single-sign-on flaw at one vendor gave an attacker the trust of a well-known security brand and instant access to a large, security-conscious audience. Under PIPEDA, an organization stays accountable for personal information it hands to a processor, even when the processor’s own system is the point of failure. A Canadian company sending customer emails through a similar platform faces the same exposure: its brand, not the vendor’s, absorbs the reputational damage when a phishing email appears to come from a trusted sender.

What to Do

Inventory every third-party platform with access to customer contact lists or the ability to send email under your domain. Confirm each vendor enforces phishing-resistant authentication on its own administrative accounts, not only on the product you buy. Add DMARC, SPF, and DKIM enforcement so a compromised vendor account is unable to spoof your exact sending domain, and build a rapid vendor-notification and takedown process so a breach reaches your incident response team within minutes, not days.

Enjoy this article? Don’t forget to share.