ChainCatcher report: Trezor, a manufacturer of Bitcoin hardware wallets, warned that a data breach occurred on Brevo, a third-party marketing platform used to send newsletters, enabling attackers to send phishing emails to 347,000 Trezor customers. The attackers exploited Trezor’s domain to send emails, making the phishing attempts more convincing; the emails contained malicious links designed to trick users into downloading applications and entering their wallet backups. Trezor stated that it disabled the compromised domain at the DNS level within 20 minutes, preventing further access to the links, but approximately 2,500 users had already clicked on them. Trezor has suspended its Brevo account to halt further email distribution and emphasized that no other Trezor systems were affected. The company also reminded users that Trezor never requests customers to provide their wallet backups. Prior to this incident, Trezor disclosed last month that its third-party fulfillment partner, ShipMonk, was compromised, resulting in the exposure of data for 11,742 customers; last week, it further revealed that the personal information—including names, email addresses, phone numbers, shipping addresses, and order numbers—of an additional 67,000 U.S. customers was exposed. Earlier this year, payment processor Global-e for the cryptocurrency wallet Ledger and wallet provider SafePal also suffered data breaches, with SafePal reporting unauthorized access to order information of approximately 39,800 customers.
Trezor Marketing Platform Compromised; 347,000 Users Targeted by Phishing Emails
ChaincatcherShare
Trezor, a hardware wallet provider featured in Bitcoin news, disclosed a phishing attack carried out through its third-party marketing platform, Brevo, impacting 347,000 users. Attackers exploited Trezor’s domain to distribute malicious links, tricking users into downloading fake apps and entering wallet backups. Trezor blocked the domain within 20 minutes, but approximately 2,500 users clicked the links. The company suspended its Brevo account and confirmed no internal systems were compromised. This on-chain incident follows previous breaches involving Trezor’s logistics partner and other wallet providers.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.