Trezor Phishing Campaign Exposes the Hidden Risks of Third Party Email Providers

Cybersecurity incidents do not always begin with a direct compromise of an organization’s own infrastructure.

Sometimes, the weakest link can be a trusted third party.

A recent incident involving Trezor demonstrates how the compromise of an external email service can be turned into a highly convincing phishing campaign targeting hundreds of thousands of users.

Trezor disclosed that approximately 347,000 newsletter addresses were affected after a security incident involving Brevo, the third party email marketing platform used for newsletter distribution. The compromised channel was then used to send phishing messages designed to convince recipients that their hardware wallets faced a critical security problem.

The incident is an important reminder that organizations must look beyond their own networks when assessing cybersecurity risk.

What Happened?

The incident began with a compromise involving Trezor’s third party email provider.

An unauthorized actor gained access to Brevo and used the platform to send messages through customer accounts, including Trezor’s email infrastructure. Trezor reported that its newsletter database contained approximately 347,000 email addresses. The company said its own wallet systems, products, and account infrastructure were not compromised.

The attackers used the trusted communication channel to distribute a fraudulent security alert.

The phishing campaign attempted to create urgency by claiming that Trezor devices were affected by a technical security problem and directed recipients toward a malicious website.

The objective was particularly serious because the attackers attempted to obtain wallet backup information from users.

Trezor responded by disabling its Brevo account and taking action against the phishing domain. The company reported that the malicious domain was taken down at the DNS level within approximately 20 minutes, limiting further access to the phishing site.

Why This Incident Is Different

Traditional phishing attacks often depend on impersonating a trusted organization from an unrelated domain.

This incident demonstrates a more concerning scenario.

When attackers compromise a legitimate third party that an organization already trusts, they may gain access to communication channels that have already established credibility with customers.

This can make phishing campaigns considerably more convincing.

Email recipients may see:

• A familiar company name
• A legitimate looking sender address
• A message appearing to come from an organization they trust
• Familiar branding and communication patterns
• A security warning designed to create urgency
• A link that appears relevant to an existing product or service

This creates a significant challenge for conventional email security controls.

The Third Party Risk Problem

Organizations frequently rely on external providers for:

• Email marketing
• Customer communications
• Cloud hosting
• Payment processing
• Customer support
• Logistics
• Analytics
• Identity management
• Software development
• Data storage
• CRM platforms
• SaaS applications

These providers become part of the organization’s operational ecosystem.

A company may have strong internal security controls while still being exposed through a third party with weaker security practices.

This is why third party risk management should be treated as an essential part of enterprise cybersecurity rather than a procurement exercise.

Organizations should understand:

• What data is shared with vendors
• Where that data is stored
• Who can access it
• How authentication is implemented
• What integrations exist
• What privileges third parties receive
• How vendor accounts are monitored
• How incidents are reported
• How quickly access can be revoked
• How long data is retained

Trusted Communication Channels Can Become Attack Channels

One of the most important lessons from this incident is that trust itself can become an attack surface.

Email infrastructure is particularly sensitive because customers naturally trust messages from organizations they already know.

If attackers gain control of a legitimate communication platform, they may not need to spoof the organization.

They can potentially use the organization’s existing communication infrastructure to distribute malicious content.

This makes security controls such as identity protection, privileged access management, authentication monitoring, domain protection, and vendor security assessments increasingly important.

Phishing Remains a Human and Technical Security Problem

Phishing is often described as a user awareness issue.

It is more accurately a combination of human, technical, identity, and organizational security risks.

Even highly security conscious users can be exposed when a phishing message appears to originate from a legitimate communication channel.

Organizations should therefore combine user awareness with technical controls.

Important defensive measures include:

• Strong multi factor authentication for email service providers
• Strict identity and access management
• Least privilege access
• Privileged account monitoring
• Continuous monitoring of third party accounts
• Domain protection and email authentication
• DMARC, DKIM, and SPF configuration
• Phishing resistant authentication where appropriate
• Security awareness training
• Vendor risk assessments
• Incident response procedures for compromised communication platforms
• Continuous monitoring for unauthorized email activity

Protecting Sensitive Information Requires Clear Security Boundaries

The Trezor incident also highlights an important principle for organizations handling sensitive information.

Third party platforms should receive only the information they actually need.

Data minimization can significantly reduce the impact of a vendor compromise.

Organizations should regularly review:

• What information is transferred to vendors
• Whether the information is necessary
• Whether sensitive data can be removed or anonymized
• How long vendors retain the information
• Whether data deletion requirements are contractually enforced
• Whether vendor access is periodically reviewed
• Whether vendors provide adequate security logging

Security requirements should also be included in vendor agreements, service contracts, and data processing arrangements.

Supply Chain Security Extends Beyond Software

Software supply chain security is receiving significant attention, but supply chain risk is broader than source code and dependencies.

Email providers, SaaS platforms, cloud services, logistics companies, customer support systems, and other external providers can all become part of an organization’s attack surface.

A mature cybersecurity program should therefore consider the entire digital supply chain.

This includes evaluating:

• Vendor security maturity
• Identity and authentication controls
• Data access requirements
• API integrations
• Administrative privileges
• Cloud security configurations
• Security monitoring capabilities
• Incident response processes
• Business continuity controls
• Regulatory and compliance requirements

Industries That Should Pay Attention

The lessons from this incident apply across many industries.

Financial Services

Banks, fintech companies, payment providers, and investment platforms routinely communicate with customers through email and digital channels.

COE Security can help financial organizations strengthen identity security, application security, phishing defenses, third party risk management, continuous monitoring, and compliance programs.

Healthcare

Healthcare organizations depend on external providers for communications, patient services, cloud applications, and data processing.

A compromised vendor can potentially create privacy and compliance risks involving sensitive information.

COE Security can help healthcare organizations strengthen data governance, vendor security assessments, application security, monitoring, and controls aligned with HIPAA requirements.

Retail and E-commerce

Retail organizations rely heavily on customer communication platforms, payment providers, marketing systems, CRM platforms, and cloud services.

COE Security can help retailers assess third party risks, secure customer facing applications, improve identity controls, strengthen monitoring, and protect sensitive customer information.

Manufacturing

Manufacturers increasingly depend on connected cloud platforms, SaaS applications, suppliers, development environments, and operational technology ecosystems.

COE Security can help manufacturing organizations evaluate third party exposure, secure applications and infrastructure, conduct penetration testing, and improve security monitoring.
Government

Government agencies rely on extensive networks of contractors, technology providers, cloud platforms, and communication services.

Third party compromise can create significant operational and regulatory consequences.

COE Security can support government organizations through security assessments, penetration testing, compliance consulting, secure development practices, monitoring, and third party risk management.

What Organizations Should Do Now

Organizations should not wait for a third party incident to discover weaknesses in their vendor security strategy.

A proactive approach should include:

  1. Maintain an inventory of critical third party services.
  2. Classify vendors according to the sensitivity of the information and access they receive.
  3. Review authentication and privileged access controls.
  4. Require appropriate security controls in vendor contracts.
  5. Monitor third party accounts and integrations.
  6. Establish clear procedures for rapidly disabling compromised vendor access.
  7. Conduct periodic vendor security assessments.
  8. Test phishing resilience through authorized security awareness programs.
  9. Review email authentication and domain protection controls.
  10. Include third party compromise scenarios in incident response exercises.
  11. Minimize the information shared with external platforms.
  12. Regularly review data retention and deletion requirements.
Conclusion

The Trezor incident demonstrates that cybersecurity cannot stop at the organization’s network perimeter.

A trusted third party can become an entry point for attackers, and legitimate communication channels can be transformed into highly effective phishing infrastructure.

The lesson is particularly important for organizations that depend on SaaS platforms, cloud providers, marketing systems, customer communication platforms, and other external services.

Strong cybersecurity requires continuous visibility across the entire digital ecosystem.

Organizations should treat third party security as an extension of their own security program, combining vendor risk management, identity protection, continuous monitoring, data governance, incident response, and security testing.

As businesses become increasingly dependent on interconnected digital services, protecting the supply chain is no longer optional. It is a fundamental part of building cyber resilience.

About COE Security

COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.

Our offerings include:

• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
• Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.

In addition, COE Security helps organizations strengthen their third party and digital supply chain security through vendor risk assessments, SaaS security reviews, identity and access management assessments, cloud security assessments, email and API security testing, application security testing, penetration testing, data governance reviews, incident response planning, and continuous security monitoring.

For organizations handling sensitive customer, financial, healthcare, government, or operational data, we help identify security gaps across internal systems and external technology providers and develop practical controls to reduce third party cybersecurity and compliance risks.

Our services can help financial services organizations strengthen customer and identity security, healthcare organizations protect sensitive information and support HIPAA aligned controls, retailers secure customer platforms and digital services, manufacturers protect connected technology ecosystems, and government organizations improve third party security, monitoring, and compliance readiness.

Follow COE Security on LinkedIn for ongoing insights into cybersecurity, safe and compliant AI adoption, third party risk, application security, and emerging cyber threats to stay updated and cyber safe.

Click to read our LinkedIn feature article