Trezor Warns Users of Newsletter Phishing Attack

  • Trezor users reported on Saturday they had received phishing e-mails from individuals that tried to lure them into downloading malicious code.
  • On Sunday Trezor confirmed that Mailchimp had its services compromised by an “insider targeting crypto companies”, and that the phishing domain had been taken down.
trezor

Shutterstock

Crypto hardware wallet provider Trezor is investigating a possible data breach that has left some of its users vulnerable to phishing attacks, the company said on Twitter on 3 April.

According to the announcement, a malicious actor had contacted several Trezor users posing as the company, asking them to download an application from “trezor.us”, a domain different from the official trezor.io. The individual tried to lure users into downloading the malicious code by claiming that Trezor had experienced a security breach, and this was a fix. Trezor tweeted:

The company initially suspected that the breach came from compromised e-mail addresses that belong to users that signed-ip for a newsletter hosted on email marketing service provider Mailchimp. After further investigation, Mailchimp confirmed that their service had been compromised by an “insider targeting crypto companies”, and that the phishing domain had been taken down. It is still unknown how many e-mail addresses have been affected by this security breach.

Trezor further said it had taken down two more domains related to the phishing attempt, and that it will stop communicating by newsletters until the “situation is resolved”. It also reminded users to use “anonymous” e-mail addresses when engaging in any crypto-related activities.

Trezor is not the first crypto-related company to experience a data breach this year. Last month, crypto financial institution BlockFi confirmed a data breach incident on one of its third-party vendors, Hubspot. BlockFi assured users at the time that their personal data — including passwords, IDs, and social security numbers — were safe as they were “never stored on Hubspot”.

Discussion
Related Coverage
Vitalik Says X Account Hacked Via SIM-Swap
  • Ethereum co-founder Vitalik Buterin has regained his T-Mobile account, which on Saturday was compromised by hackers and used to take over his X account.
  • On 9 September, hackers used a SIM-swap attack to take over Buterin’s X account, and siphon close to $700,000 in crypto by promoting a fake NFT giveaway.
September 12, 2023, 1:33 PM
Vitalik Buterin Proposes Creating an Ether Mixer

Ethereum co-founder and Vitalik Buterin speaks during TechCrunch Disrupt. 18 September, 2017, San Francisco, California.Steve Jennings/Getty Images for TechCrunch

Kroll Data Breach Compromises FTX, BlockFi Customer Information
  • A cyber security incident at bankruptcy service provider Kroll has resulted in the exposure of “non-sensitive” customer data for claimants involved in the FTX and BlockFi cases.
  • Both companies confirmed that account passwords, systems, and funds remained safe, but warned customers to be on the lookout for phishing scams.
Terra Freezes Website, Warns Against Phishing Scams
  • Blockchain network Terra said its website was compromised by hackers over the weekend, and warned users against ongoing phishing scams.
  • The platform later froze its website to prevent the hackers from exploiting it, and reminded users to avoid websites with the terra.money domain for now.