Interestana
Home/News/Trezor Email Provider Breached, Exposing Customer Data
Decrypt3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Trezor Email Provider Breached, Exposing Customer Data

Trezor Email Provider Breached, Exposing Customer Data

Hardware wallet manufacturer Trezor announced on June 18, 2024, that its email service provider, MailChimp, experienced a security breach. This incident potentially exposed the personal data of Trezor customers, including their email addresses. The breach occurred when an unauthorized third party gained access to MailChimp's internal systems, impersonating a Trezor employee. This allowed the attacker to access a list of Trezor customer email addresses. Trezor stated that the compromised data does not include sensitive information such as private keys, recovery seeds, or passwords. However, the company warned that customers might receive phishing emails or other malicious communications as a result of this data exposure. Specifically, Trezor alerted users to a fake security alert that falsely claimed a hardware flaw could expose users' recovery phrases. This alert was designed to trick users into revealing their recovery phrases, which are critical for accessing and recovering cryptocurrency funds. Trezor strongly advised its customers to be vigilant against any suspicious communications and to never share their recovery phrases or private keys with anyone. The company also emphasized that its own security measures and hardware wallets remain unaffected by this breach. Trezor has initiated an investigation with MailChimp and is working to understand the full scope of the data exposure. As a precautionary measure, Trezor has begun notifying affected customers directly via email, urging them to exercise extreme caution. The company also recommended that users review their security practices and be wary of any unsolicited requests for personal or financial information. This incident highlights the ongoing risks associated with third-party service providers and the importance of robust cybersecurity practices across the entire digital asset ecosystem. Trezor, a well-known provider of hardware cryptocurrency wallets, aims to secure digital assets by storing private keys offline, making them inaccessible to online threats. The company's products are designed to protect users from common hacking methods, but this breach underscores that even offline security can be compromised by vulnerabilities in associated services. The incident serves as a reminder for all cryptocurrency users to maintain a high level of security awareness and to follow best practices for protecting their digital assets.

Original source — read the full reporting at the publisher:

Read on Decrypt

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next