Trezor Faces Phishing Threats Following Email Provider Breach

Trezor Faces Phishing Threats Following Email Provider Breach

First seen 9 Sep 2026, 22:43 UTC HelpnetsecurityGlitchwire 66.0

Article Content

Browse articles
ThreatCluster

Trezor, a hardware wallet manufacturer, reported a breach of an unnamed third-party email provider, enabling attackers to send phishing emails from Trezor's domain. The fraudulent email, titled 'Critical Security Alert: STM32 Entropy Vulnerability,' aims to deceive recipients into compromising their wallets. This incident follows a previous breach at ShipMonk, Trezor's shipping partner, which exposed personal data of approximately 67,000 customers. The phishing attempts are part of a broader trend, with 182 security incidents reported in the first half of 2026, marking a 50% increase from the previous year. Trezor has taken down the compromised domain and is investigating the breach. The company reassured customers that its devices remain secure and advised vigilance against phishing attempts. The phishing emails exploit recent vulnerabilities in hardware wallet security to create urgency and confusion among users.

Key Points: • Trezor's email provider was breached, allowing phishing emails to be sent from its domain. • Approximately 67,000 customers are at risk due to previous data exposure from ShipMonk. • Phishing attempts are escalating in the crypto sector, with a significant rise in security incidents.

Ask AI about this cluster

Timeline

2026-08-13
ShipMonk breach disclosed
Trezor announced a breach at its shipping partner ShipMonk, exposing customer data including names and addresses.
Helpnetsecurity
2026-09-08
Trezor warns of phishing emails
Trezor disclosed that phishing emails were sent from its legitimate domain following a third-party email provider breach.
Glitchwire
2026-09-09
Trezor issues security advisory
Trezor published an advisory urging customers not to click links in the phishing email claiming a critical security alert.
Glitchwire