
➤Summary
Dark web surveillance is increasingly relevant to supply-chain phishing incidents such as the recent Trezor campaign, where attackers abused access to third-party email marketing infrastructure to target approximately 347,000 newsletter addresses. The incident did not involve a compromise of Trezor’s wallet or account systems, according to Trezor, but it demonstrated how trusted vendors can become an effective route into a highly targeted customer population.
For security teams, the incident is more than a phishing story. It highlights the relationship between third-party risk, legitimate communication infrastructure, credential exposure, malicious domains, and the underground ecosystems where stolen information can later circulate.
On September 9, 2026, Brevo, Trezor’s third-party marketing platform, experienced a security incident. Trezor said an unauthorized actor gained access to Brevo’s environment and used customer accounts to send phishing messages. Brevo’s status history confirms unauthorized access to client accounts was identified on September 10.
Trezor said approximately 347,000 email addresses from its opt-in newsletter database were targeted. The company stated that no other Trezor systems were touched and that its Brevo account was suspended to stop additional email distribution.
The phishing message was designed to look like a genuine Trezor security notification. It used the subject line “Critical Security Alert: STM32 Entropy Vulnerability” and claimed that a hardware-related vulnerability could put users’ wallet backups at risk.
Recipients were directed toward a malicious link and an application that requested their wallet backup information. Trezor subsequently took down the domain at the DNS level within approximately 20 minutes. The company said around 2,500 people had clicked the link before it was disabled.
BleepingComputer’s reporting provides additional incident context and confirms that the campaign targeted Trezor’s newsletter audience following the Brevo compromise. BleepingComputer’s report on the Trezor phishing campaign
The distinction between exposure and compromise is particularly important in this incident.
Trezor says its own wallet, account, and product infrastructure were not breached. The exposed asset was its newsletter audience maintained through the third-party email provider. Trezor also said Brevo did not store wallet passwords, wallet backups, or other wallet information.
The approximately 347,000 figure represents email addresses targeted by the phishing campaign. It should not be interpreted as 347,000 compromised cryptocurrency wallets.
The 2,500 figure represents people who clicked the malicious link before the domain was taken down. Trezor says the risk becomes materially different if a recipient entered a wallet backup into the malicious application or elsewhere online.
This distinction matters for incident response. A mailing-list exposure can create a large phishing opportunity without providing attackers with direct access to the organization’s core systems.
The campaign demonstrates a significant advantage for attackers: credibility.
A phishing message sent through compromised legitimate infrastructure can be considerably more convincing than a conventional spoofed email. The attacker does not necessarily need to compromise the primary organization when a trusted supplier already has access to customer contact data and communication workflows.
Brevo’s SAML Single Sign-On architecture is designed to authenticate users through external identity providers. Its current documentation explains that SAML authentication can grant users access to Brevo without requiring a separate Brevo password.
In this incident, reporting from SecurityWeek said Brevo later determined that an attacker had accessed 138 accounts through an SSO-related authorization problem. Six accounts were used to send phishing messages, while contacts were reportedly exported from 43 accounts.
For security leaders, this is a reminder that supplier access should be evaluated based not only on the systems a vendor can technically reach, but also on the trust that vendor commands.
The immediate phishing campaign was disrupted quickly, but the underlying customer exposure can remain useful to attackers.
An email address associated with a cryptocurrency hardware-wallet provider can be valuable for future social engineering. Attackers may use it to identify previous Trezor customers, correlate addresses with information from other breaches, or build more convincing follow-up messages.
This is where external threat intelligence becomes useful.
Dark web monitoring is not limited to looking for a single leaked password. Modern monitoring can correlate exposed credentials, stolen datasets, stealer logs, underground discussions, phishing infrastructure, and other external indicators.
DarknetSearch describes its monitoring capabilities as covering dark web and deep web sources including forums, Telegram channels, paste sites, botnet logs, and other sources of exposed information.
The objective is not to assume that every exposed email address represents a compromise. Instead, analysts can use external intelligence to establish whether an identity, domain, credential, or related indicator appears in additional threat activity.
Dark web surveillance can provide a post-incident visibility layer when organizations need to determine whether exposed information is being reused or redistributed.
For example, security teams can monitor for:
These sources should not be treated as interchangeable. A dark web forum, Telegram channel, paste site, stealer-log collection, and ransomware leak site represent different parts of the cybercrime ecosystem.
DarknetSearch’s dark web monitoring glossary explains how monitoring can be used to identify exposed information across hidden online environments while distinguishing dark web monitoring from broader threat intelligence. DarknetSearch dark web monitoring glossary
The Trezor campaign primarily involved targeted phishing, but defenders should also consider what happens if victims subsequently enter credentials or sensitive information into malicious applications.
Infostealer malware creates a different exposure pathway. Instead of extracting records from a company’s database, an infostealer can collect information from an infected endpoint, including browser credentials, cookies, autofill data, and system information. Those records may later circulate through criminal channels.
DarknetSearch’s stealer log intelligence guide explains why these records can contribute to account takeover and credential abuse. DarknetSearch stealer log intelligence guide
For SOC teams, the practical lesson is to correlate external exposure with internal telemetry. If an employee or customer identity appears in an external dataset, analysts should determine whether authentication logs, endpoint alerts, password-reset events, or suspicious sessions show related activity.
Organizations using third-party email, CRM, marketing, support, or customer-engagement platforms should treat these systems as part of the external attack surface.
A practical response includes:
This workflow is particularly relevant to MSSPs and MDR providers managing multiple clients. Continuous external monitoring can help service providers correlate customer identities, domains, exposed credentials, and threat activity rather than treating every alert as an isolated event.
The best dark web monitoring tools should provide more than keyword searching. Security teams should evaluate whether a platform can monitor relevant external sources, identify exposed credentials, analyze stealer logs, provide useful context, and support investigations without overwhelming analysts with unverified findings.
For an incident such as the Trezor campaign, useful capabilities include:
Dark web monitoring should complement, not replace, EDR, SIEM, MFA, identity security, vulnerability management, email security, and incident response.
The value comes from connecting external signals with internal evidence.
Security teams investigating a third-party phishing campaign should ask:
The last question is often overlooked. Removing a phishing domain addresses one immediate attack path, but it does not remove the underlying exposure.
Dark web surveillance cannot prevent every phishing attack. Its value is in improving external visibility by identifying exposed credentials, stolen data, threat discussions, and related indicators that may support follow-on attacks. Combined with email security, MFA, identity controls, endpoint detection, and incident response, it can help organizations detect and prioritize risks earlier.
Trezor states that its own systems, wallets, and account infrastructure were not breached in this incident. The compromise occurred at Brevo, its third-party email marketing provider, and the attackers used the access to target approximately 347,000 newsletter addresses. Trezor said no wallet backups or passwords were stored by Brevo.
Do not click the link, download the offered application, or provide a wallet backup. Trezor says it will never request a wallet backup through email. Anyone who entered a wallet backup into the malicious application or website should follow Trezor’s emergency guidance and move affected funds to a new wallet.
Phishing can create secondary exposure. Email addresses, credentials, stolen session information, or other data collected during follow-on attacks can later appear in criminal communities. Underground forum monitoring helps security teams determine whether exposed information is being redistributed or associated with additional threat activity.
The Trezor-Brevo incident shows why third-party exposure should remain part of an organization’s threat-intelligence strategy after the immediate phishing campaign ends. Monitoring exposed credentials, stealer logs, underground activity, domains, and related external indicators can provide additional context for SOC and incident-response teams. DarknetSearch can complement existing security controls by adding external threat visibility to investigations and ongoing monitoring. Explore the DarknetSearch Knowledge Center
Disclaimer: DarknetSearch reports on publicly available threat-intelligence sources. Inclusion of an organization in an article does not imply confirmed compromise. All claims are attributed to external sources unless explicitly verified.
Discover how CISOs, SOC teams, and risk leaders use our platform to detect leaks, monitor the dark web, and prevent account takeover.
🚀Explore use cases →