The email was real. That's the problem.

12.09.26 10:39 - By Shaun Barnett

Last Wednesday, a lot of people received an email from a company they'd bought something from.

It came from the company's real address. It passed every security check an email can pass. It arrived in the same inbox thread as the newsletters they'd been getting for years. Their mail provider didn't flag it, because from a technical standpoint there was nothing to flag.

It was a scam.

Not a convincing forgery. Not a lookalike domain with a swapped letter. The email was genuinely sent from the company's own email system — because criminals had broken into the company that sends the company's email.

If you've ever been told to check the sender's address before you click, this is the week that advice stopped being enough.

So let's talk about what actually happened, why it's going to keep happening, and what replaces the advice that just broke.

What happened

On Wednesday 9 September, customers of the hardware wallet makers Trezor and BitBox, and the crypto tax service CoinTracking, received urgent security warnings.


The Trezor version was headed "Critical Security Alert: STM32 Entropy Vulnerability." BitBox's said "Critical Security Alert: Microcontroller Entropy Bug Identified." Both claimed a serious hardware flaw had been found in the devices, and both asked people to enter their wallet backup — the recovery phrase that, if you hand it over, gives a stranger everything.


CoinTracking customers got a different lure, asking them to refresh their API keys.


The emails came from a genuine trezor.io address. Not a lookalike, not a swapped letter. The actual domain.


None of these companies had been hacked. Their email provider had.

Brevo, and the 120 doors

The provider is Brevo — a French platform, formerly called Sendinblue, that sends marketing and transactional email on behalf of other businesses. It's not a niche product; Brevo says it has more than 600,000 customers globally. If you've ever received a newsletter, a receipt, a shipping notification or an appointment reminder, there's a reasonable chance it travelled through a platform like this one, and a decent chance it was this one.


Brevo said on 10 September that an attacker had got into 120 of its customer accounts. In the company's words: "The bad actor used the access to send phishing emails to the client's contactbase. The access has been closed."


Read that again, because the phrasing is doing a lot of quiet work. The client's contact base. The attacker didn't need to steal an email list and send from somewhere else. They logged into the tool the company uses to email its own customers, and pressed send.


BitBox put it plainly: "Our preliminary review found that it is very likely that our newsletter provider got compromised." And added the line that should worry everyone reading this — "Multiple other Bitcoin companies got targeted as well."


Three companies have been named. One hundred and twenty accounts were accessed, on Brevo's own preliminary count. A fuller post-mortem was promised and hadn't appeared when this was written.

Why every check passed

This is the technical heart of it, and it's worth understanding even if you've never thought about email plumbing in your life, because it explains why your instincts had no chance.


Modern email has three anti-forgery systems working behind the scenes. You've never seen them, but they run on every message you receive.


SPF checks whether the server sending the email is on the list of servers allowed to send for that domain. Trezor, BitBox and CoinTracking had all authorised Brevo's servers — as they should have, since Brevo sends their mail. So the phishing passed SPF. As far as the receiving mail server was concerned, it came from an authorised source.


DKIM adds a cryptographic signature proving the message wasn't tampered with in transit and really came from who it says. The attackers were operating inside Brevo, so their messages were signed with the real keys. Valid signature.


DMARC is the policy layer that decides what to do when SPF or DKIM fails. Neither failed. DMARC had nothing to flag.


The emails weren't pretending to be legitimate. At the protocol level, they were legitimate. Sent by the right system, from the right domain, signed with the right keys, through the same pipe as every real message those companies had ever sent.


There is no version of "look closely at the sender address" that catches this. There is no hover-over-the-link trick, no check-for-spelling-mistakes rule, no gut feeling honed by twenty years of email that gets you out of it. The signal that people have been trained for a decade to rely on was, in this instance, telling the truth. It just wasn't telling them what they thought it was.

The bit that makes it worse

Trezor's customers were not a random group of people last Wednesday. A lot of them were already on a list.


In August, Trezor disclosed a breach at ShipMonk, the logistics company that packs and ships its products. The exposed data included full names, email addresses, phone numbers, shipping addresses, cities and order numbers.


The first disclosure, on 13 August, covered around 14,000 customers. Then on 4 September a second and entirely separate group surfaced: 67,000 more US customers, from orders placed between November 2019 and August 2021. Just under 81,000 people in total, across two eras of the same supplier relationship.


Here is the detail that should stay with you. Those old records weren't supposed to exist. Trezor's statement:


"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications."


The company asked. Repeatedly. Got it in writing. The data was still there, five years on, when someone came for it.


So the sequence for an unlucky Trezor customer over four weeks was: a supplier they'd never heard of leaked their name, address and phone number — then a different supplier they'd also never heard of was used to send them a perfectly authenticated email asking for the keys to their money.


Neither company was hacked. Both of their customers were.

Australia had its own version of this in the same week

On the very same day the Brevo emails went out, an Australian charity called Way Forward told its clients it had been caught in a cyber incident.


You may not know Way Forward. It's a not-for-profit that's been running since 2018, backed by the major banks, and it does something quietly valuable: it negotiates with creditors on behalf of Australians carrying unsecured debts they can't manage, and sets up a single affordable payment that it then distributes out to everyone they owe. It's free. The people who use it are, almost by definition, people for whom a missed payment is not a small thing.


The incident wasn't at Way Forward. It was at the external provider that runs its client management system.


Because payment arrangements are set up and run through that system, the system going down took the payments with it. In Way Forward's words: "As payment arrangements are initiated and managed through the affected system, this function is currently unavailable." The online eligibility tool went down too. The charity asked creditors to put a temporary payment moratorium in place so its clients' credit reports wouldn't be marked for payments that couldn't physically be made.


And it told clients to stay alert to unexpected communications — the standard warning, and the right one, because people who've just been told they're in a breach are exactly who gets phoned next.


Early indications are that the data affected related mostly to the provider's own company rather than to Way Forward's clients, and that's still being confirmed. But hold the shape of it in your head, because it's the same shape as Trezor: an organisation with a good reputation and a duty of care, a supplier doing the actual data handling, and a group of people at the end of the chain who never picked the supplier, never heard of the supplier, and absorbed the consequences.

This is now the normal way Australians get breached

It would be comforting to treat this as a crypto story, or a charity story. It isn't. It's the dominant pattern.


The Office of the Australian Information Commissioner recorded 1,205 notifiable data breaches in 2025 — the highest number in any year since the scheme began, and 8% up on 2024's 1,112. Health providers led with 225, then financial services on 157, then Australian Government agencies on 118. Most were malicious or criminal attacks: 716 of the 1,205.


The OAIC has been flagging the supplier problem specifically for years. Its own terminology for it is secondary notifications — where one breach at one provider forces a queue of other organisations to notify their own customers. In the second half of 2023, secondary notifications jumped to 121, up from 29 in the six months before. Then-Commissioner Angelene Falk's summary still holds up:


"The increased occurrence of incidents that affect multiple parties is a reason we are seeing data breaches grow in complexity, scale and impact."


And the regulator is unambiguous about where responsibility sits: when you hand your data to an organisation and that organisation hands it to a provider, the organisation you dealt with is still accountable for it. That's the law's position. It is not, unfortunately, much comfort at the moment your phone rings.


What it means for you as a person rather than a compliance department is simpler and more annoying: you cannot audit your own exposure. You chose the bank, the retailer, the clinic, the charity. You did not choose their CRM, their email platform, their fulfilment partner, their payments processor, their offshore support desk or their analytics vendor. You were never told who they were. And any one of them can put you on a list.

So what replaces "check the sender"?

Here's the good news, and it's better than it sounds. The advice that broke this week was always the weakest link in the chain, because it asked you to make a judgement call. What replaces it asks you to make no judgement at all.


One rule, and it's the whole article:

Never act on an inbound message. Go to the source yourself.


Not "decide whether the message is real." Not "look carefully." Never act on it. If an email, text or call tells you to do something — log in, verify, refresh, confirm, move your money, enter your backup — you close it, and you go to the organisation independently. Type the address you already know. Use the app you already have. Ring the number on the back of your card, or from your own last statement, not the number in the message.


The reason this works where sender-checking fails is that it doesn't care whether the message is genuine. A real email from your real bank will still be true when you get to your banking app under your own steam. A fake one evaporates. You don't have to be right about which one you're holding — which is exactly the point, because last Wednesday nobody could have been.


It costs you about ninety seconds and a small amount of feeling silly. That's the entire price.

The specific defences, in order

1. Treat urgency as the tell, not the sender.

The attackers used the word Critical in the subject line for a reason. Urgency exists to stop you doing the ninety-second check. When a message tells you something terrible will happen unless you act now, that is the single most reliable signal available to you — and unlike the sender address, it's one criminals can't stop using, because without it the scam doesn't work. IDCARE's advice is the same: end any conversation that demands immediate action.


2. Never enter a recovery phrase, seed phrase or backup anywhere. Ever.

If you hold crypto, this is the one that matters. There is no legitimate situation — no firmware update, no security audit, no vulnerability patch, no support process — in which any company needs your recovery phrase. Trezor's own advice during the incident: "Do not click it or interact with it. Never enter your wallet backup anywhere. Always confirm every action with your Trezor physically."


3. Expect the follow-up.

IDCARE describes data breaches and scams as "two sides of the same coin", and that's the mechanism to understand. Being in a breach isn't just an exposure; it's an introduction. Your details go onto a list of people who are known to be customers of a specific company, which is what makes the next message so convincing. IDCARE handled close to 100,000 engagements from Australians and New Zealanders in 2024 alone.


If you get a breach notification, assume contact is coming, and decide now how you'll handle it — before the call arrives and you have to decide under pressure.


4. Know that the good guys get impersonated too.

In August the National Anti-Scam Centre contacted more than 10,000 Australians whose details surfaced in a UK police investigation into a crime group targeting crypto exchange and hardware wallet users. It then had to issue a second warning: scammers were impersonating the NASC and the AFP, offering to help with the investigation and stealing money and information instead.


Worth memorising their line, because it's a clean rule: the NASC "will never request money or sensitive information from you, or send you a text message with links, attachments or a number to call."


5. Use an authenticator app, not SMS, wherever you're given the choice.

A phishing email that gets your password still hits a wall if the second factor is a passkey or an authenticator app. SMS codes can be phished in real time and your number can be ported away from you. This is the cheapest upgrade available and it takes ten minutes.


6. Consider a separate email address for anything financial.

Not for secrecy — for signal. If your crypto exchange, your broker and your bank are the only things that use one address, a message arriving at any other address claiming to be from them is instantly, obviously wrong. It converts a judgement call into a fact.

The wider thing worth noticing

Every one of these stories has the same structure: the organisation you trusted did not fail. Something behind it did.


That's not an argument for cynicism about the organisations. Way Forward is a good charity doing genuinely useful work for people in a hard spot. Trezor sells a product whose entire purpose is to keep your money out of reach of exactly this kind of attack, and by all accounts the devices themselves were never compromised.


It's an argument about where the risk has moved. Your data's safety is now determined less by the companies you choose than by the companies they choose. And you get no say, no visibility and no warning.


That's precisely why the Privacy Amendment (Personal Data Protection) Bill 2026 exposure draft matters, and why its proposed 72-hour deadline for notifying the Information Commissioner is more than a paperwork change. It's a draft, not law yet. When a breach runs through four organisations before it reaches you, every day of delay is multiplied down the chain.


Submissions on that draft close this Thursday, 18 September. If you've ever been on the receiving end of one of these, it's an unusually direct opportunity to say so.

If you think you clicked

Move fast, and don't sit with it alone.

  • If you entered a wallet recovery phrase, move your funds now, using a different, clean device. Speed is everything here and there is no undo.
  • If you entered a password, change it on that account and on anywhere else you've used it, starting with your email.
  • Call IDCARE on 1800 595 160. Free, Australian, and they'll build you a written plan specific to what was actually exposed. Best call you can make.
  • Report it to ReportCyber at cyber.gov.au, and to Scamwatch at scamwatch.gov.au.
  • Tell your bank if any financial detail was involved. They can watch the account and, in some cases, recall a payment.
  • Write down the timeline while it's fresh — every message, every click, every date.

And the part that needs saying every single time: this is not a failure of judgement.


The people who got that email on Wednesday did nothing wrong. They bought a product, subscribed to updates from the company that sold it, and received a message from that company's real address, correctly signed, that their mail provider delivered without so much as a warning banner. Being suspicious of that would have required suspecting an email system that had been telling them the truth for years.


The advice failed them. Not the other way round.

The thing to actually do

Pick the three organisations that could hurt you most if someone got in — for most people that's your email, your bank, and whichever account holds your money or your super.


For each one: make sure two-factor is on and using an app rather than SMS. Then make yourself a small promise that you'll never log in from a link in a message again, only from the app or an address you've typed yourself.


That's it. Ninety seconds a time, and it holds no matter how good the fake gets — because it doesn't depend on the fake being bad.


Then send this to one person who spends a lot of time in their inbox and has been told a thousand times to check the sender's address.


That advice just expired. Somebody should tell them.

SelfCybr helps Australian individuals and families see what's exposed, fix it, and learn how to stay ahead of it. No jargon, no shame, no data sold — ever. Australian-owned, Australian-hosted.

Sources & Further Reading

The Brevo incident and the phishing campaign
The ShipMonk breach
Way Forward
Australian breach statistics
Scams following breaches
Privacy reform
  • Attorney-General's Department — Privacy reform consultation (Privacy Amendment (Personal Data Protection) Bill 2026 exposure draft; submissions close 18 September 2026)
Where to get help

Shaun Barnett

Shaun Barnett