Trezor Warns 347,000 Customers After Brevo Email Breach
A Brevo security breach let attackers send phishing emails to roughly 347,000 Trezor addresses, while Trezor says its wallets and systems were unaffected.
Trezor is warning customers about a new phishing campaign after attackers compromised an email provider that the hardware crypto wallet company uses and sent roughly 347,000 malicious messages to addresses associated with its customers.
The company said the attack originated through Brevo, a marketing technology provider Trezor uses for newsletters. In its customer warning, Trezor said the phishing emails directed recipients to a malicious application designed to obtain their wallet backup password.
One subject line used in the campaign read, “Critical Security Alert: STM32 Entropy Vulnerability.” Trezor said its products, wallets and account systems were not compromised in the incident.
Brevo says attackers accessed 138 accounts
Brevo said attackers accessed 138 customer accounts and used them to distribute the phishing messages. In its incident write-up, the company said a flaw improperly scoped the attackers’ access permissions, giving them access to organisations that their accounts should not have been able to reach.
The phishing campaign posed a serious risk because a crypto wallet backup password can let an attacker take control of funds and transfer them on a public blockchain. Trezor warned customers that exposed email addresses could also be used in future phishing attempts.
Second Trezor-related breach in recent weeks
The Brevo incident follows another breach involving a Trezor vendor. In August, shipping provider ShipMonk was compromised, exposing names, phone numbers, email addresses and postal addresses belonging to at least 81,000 Trezor customers who had purchased and received wallet hardware.
After that breach, some customers received physical letters that appeared to come from Trezor. The letters included QR codes that directed recipients to fraudulent websites designed to collect crypto wallet passwords. Exposing customer contact and address information can create risks beyond online fraud for cryptocurrency owners. Such information may be used in highly targeted scams or physical attacks aimed at forcing victims to reveal credentials used to access digital assets.
Trezor said it is reevaluating its relationships with outside vendors following the incidents and urged customers to remain cautious of messages requesting wallet backup information or directing them to unfamiliar applications and websites.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0