Interestana
Home/News/Trezor Warns of Phishing Attacks After Email Provider Breach
BleepingComputer2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Trezor Warns of Phishing Attacks After Email Provider Breach

Hardware cryptocurrency wallet manufacturer Trezor issued a warning to its customers on Wednesday, detailing that threat actors have breached its third-party email provider and are now leveraging this access to conduct phishing attacks. The company stated that the attackers gained access to a list of Trezor customer email addresses, enabling them to send fraudulent communications. These phishing emails are designed to trick recipients into revealing sensitive information, such as private keys or seed phrases, which are critical for accessing and securing cryptocurrency holdings.

Trezor has emphasized that its own systems and services remain secure and have not been compromised. The breach is confined to the external email service provider, meaning the attackers did not gain direct access to Trezor's internal infrastructure or customer databases. However, the exposure of email addresses is sufficient for the threat actors to initiate targeted phishing campaigns. The company is actively working with the affected email provider to understand the full scope of the breach and to implement enhanced security measures to prevent future incidents.

In response to the threat, Trezor has advised all customers to exercise extreme caution when interacting with any unsolicited emails, especially those requesting personal information or directing users to click on suspicious links or download attachments. Customers are urged to verify the authenticity of any communication claiming to be from Trezor by independently navigating to the official Trezor website rather than relying on links provided in emails. The company also recommends enabling all available security features on their Trezor devices, such as strong PIN codes and passphrase protection, to add an extra layer of defense against potential account compromise.

This incident highlights the persistent risks associated with supply chain attacks, where vulnerabilities in third-party vendors can have direct repercussions on a company's customer base. For Trezor, a company whose core business revolves around securing digital assets, such breaches underscore the critical importance of robust vendor risk management and continuous security monitoring across its entire operational ecosystem. The company has committed to providing further updates to its customers as more information becomes available regarding the breach and the ongoing mitigation efforts.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next