Trezor disclosed that hackers who compromised 138 accounts at email marketing provider Brevo used the access to send roughly 347,000 phishing emails to its customers. The messages, disguised as security alerts, directed recipients to a fake app designed to steal their wallet backup passwords. Trezor says its own products and account systems were not breached, but the stolen credentials could let attackers drain victims' crypto holdings.
Trezor disclosed that a breach at its third-party email provider Brevo let attackers send fake security alerts to its opt-in newsletter subscribers, reaching roughly 347,000 email addresses. The fraudulent messages warned of a fake microcontroller vulnerability and pushed recipients to a malicious app requesting wallet backup phrases; Trezor says 2,500 people clicked the link before it disabled the domain within 20 minutes.
Trezor alerted customers that attackers compromised its third-party email provider and used the legitimate [email protected] address to send phishing emails warning of a fake 'STM32 Entropy Vulnerability' in its hardware wallets. The company took down the malicious domain and is investigating how attackers gained access to its email infrastructure. This follows an earlier breach disclosed in August involving shipping partner ShipMonk, which exposed personal data of roughly 81,000 customers across multiple countries.
Trezor has revised the scope of its August data breach, now saying 81,000 customers were affected instead of the roughly 14,000 first reported. The increase stems from logistics partner ShipMonk failing to delete older records as its contract required, exposing details of 67,000 additional U.S. customers who ordered between November 2019 and August 2021.