đž CASE FILE #150
Trezorâs Legitimate Email Domain Was Used to Send a Crypto Phishing Attack.
Hackers breached Trezorâs third-party email provider and sent a fake "Critical Security Alert: STM32 Entropy Vulnerability" warning designed to scare users over their recovery phrases. Trezor says the vulnerability is fake and its devices are not affected.
It follows the ShipMonk breach that exposed data from 80,689 Trezor customers.
When even the sender is legitimate, "check the email address" is no longer enough.
Trezorâs Legitimate Email Domain Was Used to Send a Crypto Phishing Attack.
Hackers breached Trezorâs third-party email provider and sent a fake "Critical Security Alert: STM32 Entropy Vulnerability" warning designed to scare users over their recovery phrases. Trezor says the vulnerability is fake and its devices are not affected.
It follows the ShipMonk breach that exposed data from 80,689 Trezor customers.
When even the sender is legitimate, "check the email address" is no longer enough.
