Recent Data Breaches Expose Trezor Customers to Phishing Attacks
Hardware crypto wallet maker Trezor is warning customers for the second time in as many months that one of the companies it relies on was hacked, exposing the data of Trezor’s customers to hackers.
Cyberattack on Brevo
In a recent blog post, Trezor reported that a cyberattack on Brevo—a marketing technology firm utilized for sending newsletters—allowed hackers to dispatch approximately 347,000 phishing emails to Trezor customers. These emails contained malicious links disguised as communications from Trezor, aimed at tricking recipients into divulging sensitive information.
The Phishing Scheme Details
When users click on the malicious link, they unwittingly download an application that prompts them for their wallet backup password. Trezor identified one of the email subject lines used in the phishing campaign as: “Critical Security Alert: STM32 Entropy Vulnerability.” This tactic illustrates the increasing sophistication of cybercriminals, as they attempt to leverage current events and vulnerabilities to manipulate victims.
Consequences of Data Breach
A stolen wallet password could grant hackers irreversible access to a person’s cryptocurrency funds on the public blockchain, raising significant concerns among crypto users. Brevo acknowledged in an incident status update that the breach stemmed from unauthorized access to 138 accounts, allowing the perpetrators to send phishing messages en masse. The company indicated that hackers exploited a flaw that improperly granted extensive access to all organizations reachable by the compromised accounts.
Impact on Trezor and Its Customers
This incident marks the second significant data breach affecting Trezor in a short span, following an earlier alert in August regarding a compromise involving one of its shipping partners, ShipMonk. That breach exposed sensitive information—including names, phone numbers, email addresses, and postal addresses—of at least 81,000 customers who had purchased Trezor wallets.
Risks Faced by Crypto Owners
The data breaches raise broader security concerns, particularly for cryptocurrency owners and other affluent individuals who may be targeted for physical threats or “wrench” attacks, where criminals use force to extract passwords from victims. Following the ShipMonk incident, some Trezor users reported receiving fraudulent letters claiming to be from Trezor, which contained QR codes linking to fake websites aimed at phishing for wallet passwords.
Trezor’s Response and Future Precautions
In light of these breaches, Trezor is diligently reevaluating its relationships with vendors and has cautioned customers that their email addresses may continue to be exploited in future phishing attacks. This proactive stance highlights the importance of vigilance and security in an increasingly digital and interconnected landscape.
To stay updated on how to protect your cryptocurrency assets, users are encouraged to exercise caution and verify the authenticity of any communications purportedly coming from Trezor or associated companies.
For more detailed information, visit the original source Here.
Image Credit: techcrunch.com





