Trezor is facing yet another security dilemma after its third-party email partner Brevo was breached, exposing Trezor users to a series of phishing emails.
The wallet maker revealed that hackers were able to access its email domain, which it’s since taken down, and is now launching an investigation.
However, Trezor stressed, “Brevo’s system holds no passwords, wallet data, or other personal information.”
Brevo is also the email provider for crypto firms BitBox , CoinTracking , Peach Bitcoin , and Blocktrainer , all of which have warned users to be wary of phishing emails.
CoinTracking phishing attempts used a fabricated breach to try and trick users, while BitBox phishing attempts warned of a microcontroller entropy bug.
Bad summer to be a Trezor partner
In August, Trezor revealed that its third-party shipping partner ShipMonk was breached, causing the details of 13,689 Trezor customers to be leaked.
The company then rev e aled a month later that ShipMonk’s leak actually impacted over 80,000 customers.
Trezor was also informed that ShipMonk hadn’t been sticking to a 90-day data deletion policy as promised.
Trezor told Protos that, despite the two customer data incidents with its third-party partners, “What has not happened, in 12 years, is a Trezor device or Trezor Suite exposing anyone’s keys or funds.”
It said, “That is the part we control end to end, and it is the part that decides whether your BTC is safe.”
As for its data policy, it said it will reduce the amount of customer information held by its partners, and that it will review “vendor relationships and security requirements in light of this incident.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
