Trezor Warns of Email Provider Breach and Phishing Campaign Targeting Crypto Wallet Users
What Happened — Threat actors compromised Trezor’s third‑party email service and began sending spoofed “critical security alert” messages that claim a hardware microcontroller vulnerability. The emails direct recipients to malicious links and aim to harvest credentials or seed phrases. Trezor confirmed the malicious domain has been taken down and is investigating how the attackers accessed the legitimate domain.
Why It Matters for Trust & Control Assurance
- Continuous vendor‑risk monitoring is essential; a breached email provider can become a conduit for credential‑theft attacks against your customers.
- Demonstrable evidence of third‑party due‑diligence (contractual security clauses, regular security assessments, and real‑time monitoring) satisfies the same control objective across NIST CSF, ISO 27001, and SOC 2.
- Phishing awareness and email‑authentication controls (DMARC, SPF, DKIM) provide the audit‑ready artifacts that a control‑assurance program expects to capture after an incident.
Who Is Affected
- Cryptocurrency wallet owners who receive the spoofed alerts.
- Customers whose personal data were exposed in a prior ShipMonk logistics breach (≈ 81 k individuals across the U.S. and several EU countries).
Recommended Actions
- Verify any Trezor‑related email through the official support portal; do not click links in unsolicited alerts.
- Review and tighten third‑party contracts to include security‑assessment clauses and breach‑notification obligations.
- Deploy DMARC, SPF, and DKIM for all outbound domains and monitor for unauthorized use.
- Capture logs of the phishing attempts as evidence for audit readiness and incident‑response reviews.
Source: BleepingComputer
Technical Notes
- Attack vector: phishing emails generated after a breach of the email service provider.
- The phishing content falsely references an “STM32 Entropy Vulnerability” that does not exist.
- Earlier, ShipMonk’s breach stemmed from a Metabase SQL‑injection zero‑day, exposing order data for 81 k customers.
Source: same as above