← Back to Tech & Science

Trezor Warns of Phishing Campaign Following Third-Party Data Breach

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

PRAGUE, Sept. 10 (AP) — Cryptocurrency hardware wallet maker Trezor warned customers on Wednesday that a breach of its third-party email provider has enabled threat actors to launch sophisticated phishing attacks targeting users with fake security alerts about a non-existent microcontroller vulnerability.

The company disclosed the incident following an investigation into unauthorized access to its communication systems. The attackers exploited the compromised email infrastructure to send fraudulent messages designed to mimic official Trezor security notifications. These messages falsely claimed that a critical flaw existed in the microcontrollers used in Trezor devices, urging recipients to download malicious software or visit counterfeit websites to update their firmware.

Trezor confirmed that no actual vulnerability exists in its hardware. The company stated that its devices remain secure and that users should ignore any unsolicited communications claiming otherwise. The phishing campaign has been identified as a primary method for threat actors attempting to steal private keys and drain digital assets from victims' wallets.

The breach appears to have originated from a compromise of Trezor's third-party email service provider, which allowed attackers to access customer contact information. Additionally, the company revealed that its logistics partner, ShipMonk, suffered a separate data breach that exposed shipping and order details for customers in several countries. The combination of these two incidents has provided threat actors with comprehensive data to craft highly targeted and credible phishing lures.

Trezor identified affected regions including the United States, Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom. Customers in these jurisdictions are at heightened risk of receiving tailored messages that reference specific order details or shipping information, increasing the likelihood of successful social engineering.

The company has advised users to verify all security communications directly through its official website and to never click on links contained in unsolicited emails. Trezor has also initiated cooperation with cybersecurity firms and law enforcement agencies to track the perpetrators and mitigate the spread of the fraudulent alerts.

While Trezor has secured its internal systems and notified impacted users, the full scope of the data exfiltration remains under assessment. It is unclear how many customers received the phishing emails or if any individuals have already fallen victim to the scam. The company has not yet disclosed whether the attackers gained access to sensitive cryptographic keys or if the breach was limited to contact and shipping information.

As the investigation continues, Trezor is working to enhance its third-party vendor security protocols to prevent similar incidents. The cryptocurrency community remains on alert as this case highlights the growing reliance of hardware wallet manufacturers on external service providers, creating potential weak points in the supply chain that cybercriminals are increasingly exploiting.

Discussion

0 / 2000