Trezor said an unauthorized actor accessed Brevo and used its domain to send phishing emails to 347,000 customers. According to NS3.AI, the emails asked recipients to download an app and enter their wallet backup.

Trezor said it took down the domain within 20 minutes. The incident follows the exposure of data from 11,742 customers last month.