Cryptocurrency Companies Hit by Widespread Phishing Attacks
A wave of phishing attacks has hit several cryptocurrency companies, with hackers hijacking emails from Trezor and Bitbox to target users. The incident occurred on September 9 and 10, with multiple bitcoin companies being targeted. According to Trezor, the attackers gained access to its legitimate domain, making it harder for users to spot phishing attempts.
Trezor sounded the alarm over a fake security warning email titled 'Critical Security Alert: STM32 Entropy Vulnerability' and warned recipients not to click any links. The company said its third-party email provider had been breached.
Bitbox found signs of a wider attack, with several other bitcoin businesses being targeted and appearing to use the same newsletter provider. Bitbox responded by sending its own phishing warning and contacting the provider.
Cointracking identified Brevo as its compromised email service provider and warned customers not to click on any links contained in the bogus message titled 'Data Breach Notice: Please refresh API Keys as soon as possible.'