Scams & Phishing News Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,119
6,100
2,168
Germany
Hardware crypto wallet maker Trezor is warning customers for the second time in as many months that one of the companies it relies on was hacked, exposing the data of Trezor’s customers to hackers.

In a blog post this week, the hardware wallet maker said a cyberattack on Brevo, a marketing tech company that Trezor uses to send newsletters, allowed hackers to send around 347,000 phishing emails to Trezor customers with a malicious link purporting to come from the wallet maker.

The link, when tapped, downloads an app that asks the victim for their wallet backup password. According to Trezor, one of the email subject lines said: “Critical Security Alert: STM32 Entropy Vulnerability.”

With a stolen wallet password, a hacker can irreversibly steal the person’s funds on the public blockchain.

Brevo said in an incident status post that the hackers were able to access 138 Brevo accounts to send out the mass volume of phishing messages. Brevo said that the hackers abused a flaw that meant the hackers’ access was “not properly scoped.” The company said that the hackers’ access was “wrongly granted” to all organizations that the hackers’ accounts could reach.

The breach highlights a common security incident, where hackers compromise data held by third-party companies that are necessary for fulfilling orders or purchases from customers. Trezor says none of its products, wallets, or account system were affected by the incident.

This is the second breach in recent weeks affecting Trezor, after the company alerted customers in August that one of its shipping partners was compromised in a data breach. The incident at the mailing company ShipMonk exposed the names, phone numbers, email addresses, and postal addresses of at least 81,000 people who bought and received Trezor wallet hardware.

The data breach could put crypto owners and other wealthy individuals at risk of targeted violence and so-called “wrench” attacks, which rely on physical attacks to extract passwords from people.

In the weeks following the breach at ShipMonk, some people have received letters by mail claiming to be from Trezor, featuring a QR code that, when scanned, opens up a fake page that attempts to steal the victim’s crypto wallet password.

Trezor said it was reevaluating its relationships with its vendors and warned customers that their email addresses may be used again for future phishing attacks.
 


Hi, the practical takeaway is that Trezor owners should treat unexpected wallet-related email, postal mail and QR-code alerts as phishing. The quoted report says Trezor’s wallet infrastructure was not breached; the immediate danger is being persuaded to disclose a recovery seed, passphrase or other wallet secret.

What this incident means​

This is a third-party communications compromise, according to the report. That distinction matters: receiving or merely opening the email does not give an attacker control of a hardware wallet. The dangerous steps are following the link, installing the offered application, and entering wallet secrets.

A genuine-looking sender address is not enough to establish authenticity when an email provider’s access has been abused. The specific breach figures and timeline in the quotation would need confirmation from the linked primary statements before being treated as independently verified facts.

What affected owners should do​

  1. Do not use links, attachments or QR codes from the message. Navigate to Trezor’s official site or open Trezor Suite independently.
  2. Never enter a recovery seed into a website or an application prompted by an email or letter. A seed is control of the wallet, not an ordinary account password.
  3. If the message was only received or viewed, delete it or report it as phishing. No wallet migration is justified solely by receiving it.
  4. If the linked application was downloaded but not opened, remove it and run the device’s normal security scan. A download alone does not prove execution or compromise.
  5. If the application was run, disconnect that computer from sensitive activity and seek individualized cleanup help from MalwareTips’ Malware Removal Assistance team. Use a separate trusted device for the wallet response.
  6. If a seed or passphrase was entered, assume it is exposed. Using a clean, trusted setup and verified wallet software, create a new wallet with a new recovery seed and transfer the assets promptly. Do not merely change a PIN: that does not invalidate a stolen seed.

Anyone affected by the earlier exposure of postal details should also be cautious about convincing letters, calls and physical-security implications. Publicly discussing wallet balances or storage locations only makes targeted social engineering easier.
 
Trezor said it was reevaluating its relationships with its vendors and warned customers that their email addresses may be used again for future phishing attacks.

Yeah you might want to do that mate. Maybe Trezor can pay personal security guard protection for each affected customer.