2026 Trezor — third-party email provider breached; phishing via [email protected]
Data compromised
Company investigating how attackers obtained access to send from the legitimate domain; phishing wave used fake “Critical Security Alert: STM32 Entropy Vulnerability” messages. Distinct from ShipMonk fulfillment-contact leak. Customer census for mailbox access not published.
Technical writeup
Verified Trezor warning — September 10, 2026 (BleepingComputer). Trezor stated its third-party email provider was breached and that phishing emails were sent using the legitimate [email protected] address, including a fake “STM32 Entropy Vulnerability / critical security alert” lure. Company said it took down the phishing domain and is investigating how attackers obtained access to the legit domain. Distinct from the August ShipMonk fulfillment breach (~80.7k customers) though both increase phishing risk. Devices/seeds unaffected. recordsAffected 0 (no published mailbox census); companyConfirmed true.
Root cause
Compromise of Trezor’s third-party email provider enabling phishing from the legitimate [email protected] domain