Trezor Email Breach Exposes 34.7 Million Users to Phishing Attacks
Trezor, a hardware wallet provider for cryptocurrency assets, recently fell victim to a security incident involving its email distribution service. The breach occurred on September 9 and affected approximately 34.7 million individuals who received phishing emails from unauthorized third-party access to Trezor's regular email distribution channel.
The incident involved the use of a third-party marketing platform called Brevo, which provides services for sending and managing corporate customer emails and newsletters. Trezor utilized Brevo for its newsletter distribution. Consequently, the unauthorized party used the compromised email distribution route to send phishing emails to multiple customers, including Trezor.
Trezor emphasized that neither its product nor wallet system was affected by the incident. Moreover, the company assured that no personal information beyond email addresses, passwords, or wallet data were stored on Brevo's system. However, Trezor acknowledged that it had not confirmed whether any mail address lists were stolen from their platform.
Despite this uncertainty, Trezor treated all 347,000 registered email addresses as potentially compromised and susceptible to future phishing attacks. The company urged users to exercise caution when receiving emails related to wallet backup information. It noted that even though a user may not have clicked on any links or entered their backup information, there would be no risk of asset loss.
Approximately 2,500 individuals received the phishing email, which had a link labeled 'Critical Security Alert: STM32 Entropy Vulnerability'. The email requested users to input their wallet backup information for recovery purposes. Trezor advised customers who had entered their backup information on the phishing site to immediately transfer their assets to a new wallet.