Trezor warns crypto owners of phishing after email partner breached
Trezor confirms customer email data exposed after marketing partner Brevo suffered a cyberattack, sending phishing emails to 347,000 users.

Stock photo for illustration only, not from the actual event
- Trezor warns customers of a data breach for the second consecutive month
- Marketing platform Brevo suffered a cyberattack exposing Trezor user emails
- Scammers dispatched around 347,000 phishing emails to crypto wallet owners
- Malicious links in emails prompted victims to download fake password-stealing apps
Hardware crypto wallet manufacturer Trezor has issued a fresh security warning to its customer base after discovering that one of its essential third-party service providers experienced a cyberattack, leading to the exposure of customer contact information.
According to security reports, the breach targeted Brevo, a marketing technology company utilized by Trezor for distributing newsletters and customer updates. The security lapse enabled malicious actors to dispatch approximately 347,000 phishing emails to Trezor customers, cleverly disguised as official communications from the hardware wallet producer.
The fraudulent messages employed alarming subject lines, such as "Critical Security Alert: STM32 Entropy Vulnerability," designed to manipulate recipients into tapping a malicious link. This link initiates the download of an unauthorized application programmed to demand the victim's wallet backup password.
Obtaining a stolen wallet password grants unauthorized individuals irreversible control to drain the victim's funds directly on the public blockchain. Trezor has emphasized that none of its internal products, physical wallets, or account management systems were compromised during this incident.
"Critical Security Alert: STM32 Entropy Vulnerability"
Subject line used in phishing emails targeting Trezor customers

Stock photo for illustration only, not from the actual event
This security setback marks the second consecutive month that Trezor customers have faced data exposure risks. In August, the company alerted users that ShipMonk, a third-party shipping and fulfillment partner, suffered a security breach that compromised the names, phone numbers, email addresses, and postal addresses of at least 81,000 buyers.
Such data exposures expose wealthy cryptocurrency owners to heightened risks of targeted harassment and physical extortion, commonly referred to as "wrench" attacks, where criminals use physical violence to coerce passwords from victims. Following the ShipMonk incident, some affected individuals even received fraudulent physical mail featuring QR codes leading to credential-harvesting websites.
This incident underscores the persistent vulnerability of supply chain security in the digital asset industry. Even when companies maintain robust internal security postures, reliance on third-party marketing and logistics vendors creates secondary attack vectors that malicious actors routinely exploit to harvest customer data.
In response to the breaches, Trezor stated it is thoroughly reevaluating its vendor relationships and cautioned customers that their exposed email addresses might be exploited in subsequent phishing campaigns.
Source: TechCrunch
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment