Key highlights:
- Trezor’s external email provider was hit by a data breach, birthing a wave of phishing attempts
- Trezor says it has taken down the affected domain while urging users not to share their wallet backup
- The incident comes amid a torrid patch for Trezor, with the firm grappling with the fallout from the ShipMonk data breach
Hardware wallet provider Trezor has confirmed that its third-party email provider has been breached, sparking a wave of aggressive phishing attempts. The breach comes days after Trezor disclosed that the personal data of over 60,000 of its customers in the US has fallen into the hands of bad actors.
Trezor warns users of phishing attempts after third-party email breach
According to an
Scores of Trezor users have confirmed receiving the phishing emails, with a majority saying the phishing email is “quite convincing” because it comes from the official Trezor domain. There are fears that tens of millions worth of cryptocurrencies could be lost to bad actors from unsuspecting Trezor users.
“Our third-party e-mail provider has been breached,” said Trezor. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt.”
Trezor says it has taken down the domain and launched a full-scale investigation into the security vulnerability. The team has since sent an official email warning users about the incident and posted a disclaimer on its official website.
A rough patch for Trezor
The latest incident comes on the heels of a rough patch for Trezor, with the hardware wallet provider grappling with third-party security breaches. At the start of August, Trezor’s shipping partner, ShipMonk, suffered a security breach, leaking the personal data of over 13,000 customers.
As Trezor raced to put out the fire from the incident, fresh information came to light that the scale of the ShipMonk breach was larger than expected. Last week, Trezor confirmed that 67,000 of its US customers were affected by the data breach, increasing the risk of targeted phishing.
Barely a week after the disclosures, the phishing attempts and social-engineering attacks have begun. A handful of Trezor users have reported receiving fake letters from Trezor, urging them to scan a QR code to migrate their holdings for safekeeping.
Apart from the social engineering scams, there are concerns over the possibility of physical crypto thefts stemming from the leaked shipping addresses. Meanwhile, Trezor says it is racing to ship out an Anonymous Delivery Option for customers to prevent a future data breach of this magnitude.
Source:: Trezor Hit by Third-Party Email Breach as Phishing Attempts Spike