Trezor has recently issued another security reminder to its users. The company stated that its collaborative email service provider, Brevo, was hacked, resulting in the exposure of some customer data. Subsequently, the attackers used this information to send large-scale phishing emails. Trezor claimed that its own products, wallet, and account systems were not affected by this incident.
Brevo account was used for mass distribution of phishing emails
Brevo stated in the incident description that hackers gained access to 138 Brevo accounts and used them to send a large amount of phishing messages. The company mentioned that the issue was related to a flaw in permission control, which allowed attackers to access beyond the intended limits and inadvertently reached all organizations that these accounts could access.
For users of crypto assets, the risks associated with such incidents are not limited to email leaks. If victims enter their wallet passwords or recovery information on fraudulent websites, the assets on the blockchain could be quickly transferred away, and in most cases, they would be irretrievable.
For the second time in two months, users of Trezor are affected.
This is already the second data security incident in nearly two months that has affected users of Trezor. In August of this year, Trezor reminded its customers that its logistics partner, ShipMonk, had experienced a data breach, which affected at least 81,000 users who made purchases and received their goods.
The data exposed at that time included names, phone numbers, email addresses, and mailing addresses. Once such information is combined for use, it not only increases the success rate of targeted scams but also makes it easier for attackers to impersonate official customer service representatives, logistics companies, or after-sales channels.
The risk of offline letters and violent threats is on the rise.
In the weeks following the ShipMonk incident, some users have begun receiving paper letters pretending to be from Trezor. These letters include QR codes that, when scanned, direct users to fraudulent websites. There, users are induced to enter their wallet passwords, resulting in the theft of their encrypted assets.
Foreign media pointed out that such leaks may also expose crypto asset holders to more serious personal risks, including so-called "wrench attacks" where victims are threatened or directly subjected to violence to force them to hand over their passwords. Trezor stated that they are re-evaluating their partnership with the supplier and reminded users that the relevant email addresses may still be used for phishing attacks in the future.










