Trezor warns users of email provider breach, phishing attacks
-
Trezor has issued a warning to its customers after threat actors compromised a third-party email provider and began using the access to launch phishing attacks against users. The hardware wallet maker disclosed the incident on Wednesday, confirming that the breach occurred at an external email service rather than within its own infrastructure.
Because the compromised system was used to send legitimate Trezor communications, attackers may be able to craft convincing phishing messages that appear to come from the company. This type of attack is particularly dangerous for hardware wallet users, since phishing pages often impersonate wallet vendors to trick victims into entering their recovery seed phrase. It is worth reiterating that Trezor never asks users for their recovery seed, and anyone who obtains that phrase gains full control of the associated funds.
Users should treat any unexpected email referencing Trezor with caution, avoid clicking links or opening attachments, and navigate directly to the official website if they need to verify account or device information. Recovery seed phrases should never be entered into any website, email form, or pop-up, regardless of how legitimate the request appears.
Source: Publication Name
Have you or anyone in your circle received suspicious emails referencing Trezor since this disclosure?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login