Trezor Warns of Phishing Email After Third-Party Email Provider Breach

iconAMBCrypto
Share
AI summary iconSummary
Trezor has issued a warning about a phishing email linked to a breach of one of its third-party email providers. The email falsely claims to highlight a security risk and urges users not to click on any links. The company has taken down the malicious domain and is investigating. This incident follows a prior breach involving its shipping provider, ShipMonk, which impacted over 80,000 customers. Traders are advised to assess the risk-to-reward ratio before responding to unsolicited messages. Understanding key levels of support and resistance can help in identifying potential threats in trading decisions.

Trezor has warned customers about a phishing email sent after attackers breached one of its third-party email providers.

The email warns about a major Trezor wallet security risk, but the warning is false, says the firm, and it advises recipients not to click links.

Fake email warns of Trezor wallet flaw

The subject line of the phishing email is “Critical Security Alert: STM32 Entropy Vulnerability.”

AD

It almost looks as though the text is trying to trick the recipients into believing their hardware wallets are immediately at risk. Clicking the link may lead unsuspecting victims to a website asking them to provide confidential details of their wallets, etc.

In a post, Trezor said:

The email…is not coming from us, and it’s a phishing attempt.

The company has taken down the domain involved and is investigating how the attackers gained access to a legitimate domain.

Because the email came from a genuine domain, some users might be convinced that it is real. Attentive users usually check the sender’s address before trusting an email, but because it’s an original domain, a fraudulent message may appear real.

Trezor has not revealed the name of the affected email provider, nor has it said how many of its customers received the fraudulent message or whether their details were accessed

In addition, it has not reported any loss of cryptocurrency due to the campaign.

A separate third-party breach

There was a breach some weeks back involving Trezor’s shipping provider, ShipMonk.

This exposed names, email addresses, phone numbers, and delivery addresses, but Trezor later said 67,000 more customers have also been affected in the US.

However, the latest email provider targeted phishing campaign did not come from ShipMonk, and Trezor has neither attributed the incidents together nor claimed that the same attackers were responsible for both incidents.

Customers who received the new email should avoid its links and delete the message. They should also never enter their wallet backup on a website or share it with anyone.


Final Summary

  • Trezor says attackers breached a third-party email provider and circulated a fake security warning.
  • Trezor has shut down that domain but has yet to reveal the provider used to send out the emails or the number of affected users.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.