Trezor's email vendor breached, used to send fake security-alert phishing emails
Trezor alerted customers that attackers compromised its third-party email provider and used the legitimate [email protected] address to send phishing emails warning of a fake 'STM32 Entropy Vulnerability' in its hardware wallets. The company took down the malicious domain and is investigating how attackers gained access to its email infrastructure. This follows an earlier breach disclosed in August involving shipping partner ShipMonk, which exposed personal data of roughly 81,000 customers across multiple countries.