Skip to content
Trezor Third-Party Email Provider Compromised; Phishing Emails in Circulation

Trezor Third-Party Email Provider Compromised; Phishing Emails in Circulation

Kucoin • September 10, 2026

ME News reports that on September 10 (UTC+8), hardware wallet provider Trezor disclosed that its third-party email service provider was compromised, leading to the spread of phishing emails. Trezor explicitly stated that these emails were not sent by the official team, has immediately taken down the related domains, and is conducting an investigation. Users are advised not to click on any suspicious links.

Previously, on August 13, Trezor revealed a data breach involving its fulfillment partner ShipMonk, exposing personal data of 13,689 Trezor customers. Among them, 11,742 customers had their full names, phone numbers, email addresses, and shipping addresses stolen, while 1,947 customers had their names, cities, and email addresses leaked. Trezor’s own systems were not breached; devices, private keys, and wallet backups remain unaffected, and the scope of the breach is currently contained. (Source: BlockBeats)

Extracted Entities

Attack Types (2)

Companies (2)

MITRE ATT&CK (1)