← Trezor

2026 Trezor — third-party email provider breached; phishing via [email protected]

2026 Unknown records affected Share on X

Data compromised

Company investigating how attackers obtained access to send from the legitimate domain; phishing wave used fake “Critical Security Alert: STM32 Entropy Vulnerability” messages. Distinct from ShipMonk fulfillment-contact leak. Customer census for mailbox access not published.

Technical writeup

Verified Trezor warning — September 10, 2026 (BleepingComputer). Trezor stated its third-party email provider was breached and that phishing emails were sent using the legitimate [email protected] address, including a fake “STM32 Entropy Vulnerability / critical security alert” lure. Company said it took down the phishing domain and is investigating how attackers obtained access to the legit domain. Distinct from the August ShipMonk fulfillment breach (~80.7k customers) though both increase phishing risk. Devices/seeds unaffected. recordsAffected 0 (no published mailbox census); companyConfirmed true.

Root cause

Compromise of Trezor’s third-party email provider enabling phishing from the legitimate [email protected] domain

References