LmCast :: Stay tuned in

Trezor warns users of email provider breach, phishing attacks

Recorded: Sept. 10, 2026, 7 a.m.

Original Summarized

Trezor warns users of email provider breach, phishing attacks

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Trezor warns users of email provider breach, phishing attacks

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityTrezor warns users of email provider breach, phishing attacks

Trezor warns users of email provider breach, phishing attacks

By Sergiu Gatlan

September 10, 2026
02:56 AM
0

Cryptocurrency hardware wallet maker Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks.
Affected customers received fake "critical security alert" emails from help@trezor.io claiming that a "hardware microcontroller vulnerability" in the STM32 microcontrollers used by Trezor cold storage wallets could expose their seeds to brute-force cracking.
The company said that it's investigating the breach and that the domain has been taken down to stop the attacks.
"Our third-party e-mail provider has been breached. Please be aware that the email named 'Critical Security Alert: STM32 Entropy Vulnerability' is not coming from us, and it's a phishing attempt. Do not click on any link," Trezor warned.
"We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain."

Trezor phishing email (Geo Soul)
​Trezor also disclosed a data breach in August after attackers hacked ShipMonk, its shipping and logistics provider, and stole customers' order data, including full names, shipping addresses, email addresses, and phone numbers.
While the company initially said the incident affected nearly 14,000 customers, a Friday update warned that a follow-up investigation found the breach affected an additional 67,000 U.S. customers, bringing the total to 81,000.
As Trezor explained, the data breach also impacted customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026. While it didn't say how ShipMonk's systems were breached, breach notification emails seen by BleepingComputer said the attackers exploited a vulnerability in the Metabase analytics platform.
In early August, Metabase said the threat actors exploited a critical SQL injection zero-day vulnerability to breach customer instances, gain administrator access, and steal data.
BleepingComputer has also learned that ShipMonk received extortion emails from the ShinyHunters extortion gang after the breach.
In January 2024, Trezor disclosed another data breach after its third-party support ticketing portal was compromised and the attackers accessed data (e.g., names, usernames, and email addresses) from roughly 66,000 users.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
How MSPs can catch phishing attacks email filters missMan gets six years for hacking 750 women's Snapchat accountsShinyHunters extortion gang claims Odido breach affecting millionsBigBear Microsoft 365 phishing service bypassed MFA at 258 organizationsTrezor discloses data breach affecting nearly 14,000 customers

Breach
Email
Phishing
Trezor

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

N-able patches max severity N-central flaw amid ongoing attacks

Sponsor Posts

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

CTI Starter Kit + 2026 SANS CTI Survey

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

Overdue a password health-check? Audit your Active Directory for free

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Cryptocurrency hardware wallet maker Trezor alerted its customers regarding a data breach affecting its third-party email provider, warning that threat actors were utilizing this breach to conduct phishing attacks. Customers were targeted with fraudulent emails appearing to come from help@trezor.io, which falsely claimed a vulnerability in the STM32 microcontrollers used in Trezor cold storage wallets, suggesting their seeds were exposed to brute-force cracking. Trezor emphasized that this specific email was a phishing attempt and instructed recipients not to click any links, noting that the company had taken down the compromised domain while investigating the method of access.

Beyond the phishing warning, Trezor disclosed further data breaches involving partners and services. In August, attackers successfully hacked ShipMonk, the company's shipping and logistics provider, to steal customer order data, including full names, shipping addresses, email addresses, and phone numbers. While the initial notification affected nearly 14,000 customers, a subsequent investigation revealed that the scope expanded to include an additional 67,000 U.S. customers, bringing the total affected to 81,000 customers. This data breach also extended to customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026. The security failure in ShipMonk was traced to the exploitation of a vulnerability within the Metabase analytics platform, which had itself leveraged a critical SQL injection zero-day vulnerability to gain administrator access and exfiltrate data in early August.

Furthermore, Trezor had previously disclosed a separate data breach in January 2024, resulting from the compromise of its third-party support ticketing portal. Attackers accessed personal information, including names, usernames, and email addresses, belonging to approximately 66,000 users. This sequence of events highlights systemic risks arising from the reliance on third-party providers and interconnected systems in handling sensitive customer and operational data. The article also contextualizes the general security landscape, noting that once attackers gain valid credentials, the effectiveness of prevention measures diminishes significantly, as prevention scores drop sharply after initial access.