Trezor warns users of email provider breach, phishing attacks

Summary

Hardware wallet manufacturer Trezor has alerted its customers to ongoing phishing attacks. These attacks are being carried out by threat actors who successfully breached Trezor's third-party email provider, gaining access to customer contact information.

IFF Assessment

FOE

This incident represents a direct threat to Trezor users as compromised email lists are being used for targeted phishing attacks.

Defender Context

This incident highlights the importance of supply chain security, as a breach at a third-party provider can have direct downstream consequences for customers. Defenders should be aware of the increased risk of sophisticated phishing campaigns targeting users whose data has been exposed through such breaches, and educate users to be extra vigilant.

Read Full Story →