HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Trezor Warns of Email Provider Breach and Phishing Campaign Targeting Crypto Wallet Users

Trezor disclosed that its email service provider was breached, leading to spoofed security‑alert emails aimed at wallet owners. The incident underscores the need for continuous vendor‑risk monitoring and audit‑ready evidence of email‑authentication controls.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Trezor Warns of Email Provider Breach and Phishing Campaign Targeting Crypto Wallet Users

What Happened — Threat actors compromised Trezor’s third‑party email service and began sending spoofed “critical security alert” messages that claim a hardware microcontroller vulnerability. The emails direct recipients to malicious links and aim to harvest credentials or seed phrases. Trezor confirmed the malicious domain has been taken down and is investigating how the attackers accessed the legitimate domain.

Why It Matters for Trust & Control Assurance

  • Continuous vendor‑risk monitoring is essential; a breached email provider can become a conduit for credential‑theft attacks against your customers.
  • Demonstrable evidence of third‑party due‑diligence (contractual security clauses, regular security assessments, and real‑time monitoring) satisfies the same control objective across NIST CSF, ISO 27001, and SOC 2.
  • Phishing awareness and email‑authentication controls (DMARC, SPF, DKIM) provide the audit‑ready artifacts that a control‑assurance program expects to capture after an incident.

Who Is Affected

  • Cryptocurrency wallet owners who receive the spoofed alerts.
  • Customers whose personal data were exposed in a prior ShipMonk logistics breach (≈ 81 k individuals across the U.S. and several EU countries).

Recommended Actions

  • Verify any Trezor‑related email through the official support portal; do not click links in unsolicited alerts.
  • Review and tighten third‑party contracts to include security‑assessment clauses and breach‑notification obligations.
  • Deploy DMARC, SPF, and DKIM for all outbound domains and monitor for unauthorized use.
  • Capture logs of the phishing attempts as evidence for audit readiness and incident‑response reviews.

Source: BleepingComputer

Technical Notes

  • Attack vector: phishing emails generated after a breach of the email service provider.
  • The phishing content falsely references an “STM32 Entropy Vulnerability” that does not exist.
  • Earlier, ShipMonk’s breach stemmed from a Metabase SQL‑injection zero‑day, exposing order data for 81 k customers.

Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →