logo

Trezor warns users of email provider breach, phishing attacks

ID: 8240092e-0edc-5e01-a0f8-012f2ef7dac5

STIX ID: report--8240092e-0edc-5e01-a0f8-012f2ef7dac5

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-09-10

Date Updated: 2026-09-10

Author: Sergiu Gatlan

...
...

Trezor warned customers that attackers who breached its third-party email provider are sending phishing emails impersonating Trezor about an alleged STM32 hardware vulnerability; the company has taken down the malicious domain and is investigating. The report also recalls a related data breach via shipping vendor ShipMonk that exposed order data for about 81,000 customers after threat actors exploited a critical SQL injection zero-day in Metabase, with extortion attempts linked to the ShinyHunters gang.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.