Bitcoin Magazine
Trezor Reveals Another Data Breach After Scammers Target Marketing Platform
Hardware wallet manufacturer Trezor has issued a warning that a security breach affecting the third-party marketing platform it relies on for newsletters has enabled criminals to launch phishing campaigns against its users.
On Wednesday, the company announced that an unauthorized party gained entry into Brevo’s system, subsequently dispatching emails to 347,000 Trezor customers. Brevo is a communication service utilized by organizations for customer outreach.
The fraudsters successfully leveraged Trezor’s domain name to distribute the message, enhancing the credibility of the phishing scheme. The email featured a malicious link directing users to download an application and input their wallet backup.
This incident follows last month’s announcement from Trezor indicating that data belonging to 11,742 customers was compromised following a security incident at its third-party fulfillment vendor, ShipMonk.
Furthermore, Trezor reported last week that an additional 67,000 U.S. customers experienced leaks of their names, email addresses, phone numbers, shipping locations, and order numbers during that breach.
“We took down the domain at the DNS level within 20 minutes, preventing the link from working for anyone else and limiting access to 2,500 people who had clicked it before we took it down,” Trezor stated on Wednesday.
“These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched,” Trezor noted further.
“We have suspended the Brevo account to stop further email distribution.”
Trezor reiterated to users that the company never requests wallet backups.
Throughout the year, malicious actors have repeatedly targeted consumer data. For instance, scammers exploited crypto wallet provider Ledger’s payment processor, Global-e, to obtain customer data for phishing emails.
Additionally, competitor wallet provider SafePal disclosed a data breach last month involving unauthorized access to the order details of roughly 39,798 customers, which included sensitive personal information like names, home addresses, and purchase histories.
Frequently Asked Questions
What caused the Trezor data breach?
An unauthorized actor gained access to Brevo, the third-party marketing platform used by Trezor to send customer newsletters.
How many customers received the phishing email?
The unauthorized emails were sent to 347,000 Trezor customers.
What did the malicious email ask users to do?
The email contained a malicious link urging users to download an app and enter their wallet backup.
How quickly did Trezor respond to the incident?
Trezor disabled the compromised domain at the DNS level within 20 minutes.


