【Trezor Marketing Platform Hacked Leading to 347,000 Users Receiving Phishing Emails】
Trezor’s third-party marketing platform Brevo suffered a data breach. The attackers used Trezor’s domain to send phishing emails containing malicious links to 347,000 customers, tricking users into downloading an app and entering their wallet backups. Trezor said it shut down the relevant domain within 20 minutes to prevent the links from working, but about 2,500 people had already clicked, and it has since suspended the Brevo account. The incident continues Trezor’s recent pattern of supply-chain security issues. Last month, its partner ShipMonk leaked data for 11,742 customers, and just last week, personal information of 67,000 U.S. customers was exposed. Although the official statement says other systems were not affected beyond the marketing platform, repeated supply-chain security incidents could erode market trust in hardware wallet providers. Next, attention should be paid to whether further security patches are released and whether there are public reports of user asset losses.
Trezor’s third-party marketing platform Brevo suffered a data breach. The attackers used Trezor’s domain to send phishing emails containing malicious links to 347,000 customers, tricking users into downloading an app and entering their wallet backups. Trezor said it shut down the relevant domain within 20 minutes to prevent the links from working, but about 2,500 people had already clicked, and it has since suspended the Brevo account. The incident continues Trezor’s recent pattern of supply-chain security issues. Last month, its partner ShipMonk leaked data for 11,742 customers, and just last week, personal information of 67,000 U.S. customers was exposed. Although the official statement says other systems were not affected beyond the marketing platform, repeated supply-chain security incidents could erode market trust in hardware wallet providers. Next, attention should be paid to whether further security patches are released and whether there are public reports of user asset losses.