By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Trezor Confirms Email Provider Data Breach Affecting Crypto Owners
Hardware crypto wallet manufacturer Trezor confirmed on June 18, 2024, that a data breach occurred within one of its third-party service providers, specifically an email marketing platform. This incident has led to the exposure of the email addresses of hundreds of thousands of Trezor customers. The company stated that while email addresses were compromised, no sensitive personal data such as private keys, passwords, or funds stored in wallets were affected. The breach was identified on June 17, 2024, and Trezor was notified by the affected provider on the same day. This marks the second instance of a data breach impacting a service Trezor utilizes, following a similar incident in late 2023 involving a different vendor. In the previous breach, customer data was also accessed through a third-party CRM system. Following the latest incident, Trezor has advised its customers to be vigilant against phishing attempts and potential scams. The company emphasized that it will never ask for sensitive information via email or unsolicited communications. Trezor's hardware wallets are designed to store cryptocurrency private keys offline, providing a layer of security against online threats. However, the company acknowledges that customer email addresses, when exposed, can be exploited by malicious actors for targeted phishing campaigns. These campaigns often aim to trick users into revealing login credentials or downloading malware. Trezor has stated it is working closely with the affected email provider to understand the full scope of the breach and to implement enhanced security measures. The company is also reviewing its vendor management protocols to mitigate future risks. Trezor's primary focus remains on ensuring the security of its users' digital assets, which are protected by the physical security of the hardware wallet and the user's own security practices. The incident underscores the broader cybersecurity challenges faced by companies that rely on third-party vendors, as a vulnerability in one service can have cascading effects on its clients and their customers. The cryptocurrency industry, in particular, is a frequent target for cybercriminals due to the high value of digital assets. Trezor has a history of prioritizing security, with its devices employing robust encryption and requiring physical interaction for transaction authorization. Despite these measures, the exposure of email addresses presents a new vector for potential attacks against its user base. The company has committed to transparency and will provide further updates as more information becomes available regarding the breach and its remediation efforts. Customers are encouraged to monitor their communications for suspicious emails and to ensure they are using the latest firmware for their Trezor devices.
Original source — read the full reporting at the publisher:
Read on TechCrunchGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.