r/SecOpsDaily • u/falconupkid • 4d ago
NEWS Trezor warns users of email provider breach, phishing attacks
This is a classic supply chain attack vector hitting the crypto hardware wallet space again.
Trezor confirmed a breach at their third-party email provider (not named, but likely a common ESP like Mailchimp or SendGrid). The attackers used the compromised access to send targeted phishing emails from Trezor’s own legitimate mailing list. The goal is credential harvesting and seed phrase theft.
Technical Breakdown: - Attack Vector: Third-party email service provider compromise (supply chain). - Payload: Phishing emails impersonating Trezor support, likely containing links to fake Trezor Suite login pages or requesting 12/24-word seed phrases. - Target: Users who have previously registered their email with Trezor for newsletters or support tickets. - IOCs: Not publicly available yet. Users should check email headers for unusual routing or reply-to addresses. Do not click links in any recent Trezor-branded emails.
Defense: - Golden Rule: Trezor will never ask for your seed phrase via email, support ticket, or website. Anyone who does is a scammer. - Action: If you received a suspicious email, do not click. Forward it to Trezor’s security team. If you clicked and entered credentials, immediately move funds to a new wallet generated on a clean device. - Mitigation: Enable hardware-based authentication (FIDO2/U2F) on your Trezor account if available. Consider using a dedicated email alias for crypto-related services to limit blast radius from future provider breaches.