Trezor warns users of email provider breach, phishing attacks
Trezor warned customers that threat actors who breached its third-party email provider are conducting phishing attacks targeting its users. The phishing emails impersonate Trezor and claim a critical hardware vulnerability, attempting to trick recipients into clicking malicious links. Trezor has taken down the fraudulent domain and is investigating the breach. This incident follows a prior data breach involving Trezor's shipping provider ShipMonk, which exposed customer order data affecting tens of thousands of users across multiple countries. The phishing attack leverages compromised email infrastructure rather than a direct vulnerability in Trezor products.
AI Analysis
Technical Summary
Threat actors breached a third-party email provider used by Trezor and sent phishing emails to Trezor customers. These emails falsely claim a hardware microcontroller vulnerability in Trezor wallets to lure users into clicking malicious links. Trezor has disabled the phishing domain and is investigating how the attackers accessed their legitimate domain. This phishing campaign is related to a broader context of data breaches affecting Trezor customers, including a significant breach of ShipMonk, Trezor's shipping and logistics provider, which was exploited via a critical SQL injection zero-day in the Metabase analytics platform. The attackers used stolen customer data to facilitate targeted phishing attempts.
Potential Impact
The phishing emails pose a risk of credential theft or further compromise if users click on malicious links. While no direct compromise of Trezor hardware wallets has been reported, the breach of the email provider and prior data breaches expose customer contact information, increasing the risk of targeted social engineering attacks. The incident undermines customer trust and may lead to financial or identity theft if phishing attempts succeed.
Mitigation Recommendations
Trezor has taken down the phishing domain and is investigating the breach. Customers are advised not to click on any links in the phishing emails and to treat any unexpected security alerts with caution. No direct vulnerability in Trezor hardware has been confirmed. Users should verify communications through official Trezor channels. Since the breach involves a third-party email provider, remediation is managed by Trezor and their providers. Monitoring for suspicious emails and educating users about phishing risks remain important.
Affected Countries
United States, Brazil, Colombia, Italy, Portugal, Sweden, United Kingdom
Trezor warns users of email provider breach, phishing attacks
Description
Trezor warned customers that threat actors who breached its third-party email provider are conducting phishing attacks targeting its users. The phishing emails impersonate Trezor and claim a critical hardware vulnerability, attempting to trick recipients into clicking malicious links. Trezor has taken down the fraudulent domain and is investigating the breach. This incident follows a prior data breach involving Trezor's shipping provider ShipMonk, which exposed customer order data affecting tens of thousands of users across multiple countries. The phishing attack leverages compromised email infrastructure rather than a direct vulnerability in Trezor products.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Threat actors breached a third-party email provider used by Trezor and sent phishing emails to Trezor customers. These emails falsely claim a hardware microcontroller vulnerability in Trezor wallets to lure users into clicking malicious links. Trezor has disabled the phishing domain and is investigating how the attackers accessed their legitimate domain. This phishing campaign is related to a broader context of data breaches affecting Trezor customers, including a significant breach of ShipMonk, Trezor's shipping and logistics provider, which was exploited via a critical SQL injection zero-day in the Metabase analytics platform. The attackers used stolen customer data to facilitate targeted phishing attempts.
Potential Impact
The phishing emails pose a risk of credential theft or further compromise if users click on malicious links. While no direct compromise of Trezor hardware wallets has been reported, the breach of the email provider and prior data breaches expose customer contact information, increasing the risk of targeted social engineering attacks. The incident undermines customer trust and may lead to financial or identity theft if phishing attempts succeed.
Defensive Guidance
Trezor has taken down the phishing domain and is investigating the breach. Customers are advised not to click on any links in the phishing emails and to treat any unexpected security alerts with caution. No direct vulnerability in Trezor hardware has been confirmed. Users should verify communications through official Trezor channels. Since the breach involves a third-party email provider, remediation is managed by Trezor and their providers. Monitoring for suspicious emails and educating users about phishing risks remain important.
Affected Countries
Technical Details
- Classification
- {"confidence":0.69,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/","fetched":true,"fetchedAt":"2026-09-10T07:07:20.558Z","wordCount":634}
Threat ID: 6aa25728acd9273b49b35953
Added to database: 09/10/2026, 07:07:20 UTC
Last enriched: 09/10/2026, 07:07:30 UTC
Last updated: 09/10/2026, 14:52:58 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.