Crypto Companies Warn Customers About Phishing Emails Through Compromised Mailing Infrastructure
Crypto companies Trezor and Bitbox are warning customers about phishing emails sent through compromised mailing infrastructure. The emails, which appeared to be legitimate security notices, were actually designed to steal information from cryptocurrency users.
Trezor said its third-party email provider had been breached, allowing hackers to send fake messages with links that could compromise user accounts. The company's investigation is ongoing, but it has already taken down the malicious domain.
Bitbox reported a similar incident, with multiple bitcoin companies targeted by the same newsletter provider, Brevo. Cointracking, another cryptocurrency firm, also identified Brevo as its compromised email service provider and warned customers not to click on any links in a phishing message they received.
The timing of these incidents is particularly concerning, given that both Trezor and SafePal suffered customer-data leaks in August. While neither incident compromised seed phrases or private keys, the leaked information could still be used for more convincing phishing attempts.