Hardware wallet maker Trezor confirmed a data breach affecting its email provider, exposing hundreds of thousands of crypto owners to targeted scams. This marks the second breach involving a third-party service that Trezor depends on.
Trezor disclosed that scammers are actively targeting users following a data breach at one of its email service providers. The breach compromised customer email addresses, which attackers are now leveraging to conduct phishing campaigns and other fraud schemes against cryptocurrency holders.
The affected users received unsolicited communications attempting to trick them into revealing private keys or transferring assets. Scammers have crafted messages impersonating Trezor support, exploiting the legitimate contact information obtained through the breach.
This incident represents a significant security lapse for Trezor, which markets its hardware wallets as a secure method for storing cryptocurrency offline. While the wallet devices themselves remain isolated from the breach, the compromised email data creates a direct attack vector for social engineering.
Trezor has not disclosed the exact number of affected users, though the company confirmed the scope spans hundreds of thousands. The hardware wallet maker recommended users enable two-factor authentication on associated accounts and remain vigilant for phishing attempts.
The breach also raises questions about Trezor's vendor management practices. This is the second security incident involving a third-party service provider that Trezor relies on, suggesting potential gaps in supply chain security oversight.
Crypto users are advised to assume their email addresses may be compromised and to scrutinize any communications claiming to be from Trezor or its support team. Official communications from Trezor can be verified through the company's website and authenticated social media channels.
Trezor has not announced whether customers will receive compensation or credit monitoring services in response to the breach.
A security researcher has identified a method for untrusted websites to freeze macOS systems, dubbed "The Deathray." The technique exploits browser behavior to render machines unresponsive.
A US judge dismissed two lawsuits against LinkedIn for scanning users' browser extensions, ruling that downloading extensions constitutes voluntary data exposure. The Microsoft subsidiary prevailed on its motion to dismiss.
Florida's Department of Highway Safety and Motor Vehicles confirmed a breach of its DAVID driver database after attackers exploited stolen credentials from a police department employee.
Threat actors are chaining critical vulnerabilities in JFrog Artifactory to bypass authentication and deploy Rust-based backdoors on self-hosted servers. The attacks grant attackers administrative privileges on vulnerable instances.