NG Solution Team
Cybersecurity

Trezor Email Provider Breach Used to Send STM32 Phishing

Hardware wallet maker Trezor told customers on Wednesday that attackers who broke into its third-party email provider are using that access to send phishing messages from the company’s genuine support address, [email protected], under the subject line ‘Critical Security Alert: STM32 Entropy Vulnerability.’

The emails claimed a flaw in the STM32 microcontrollers inside Trezor cold storage devices could let attackers brute-force a user’s seed phrase.

Trezor said the domain used in the campaign has been taken down while it works out how the attackers reached its legitimate sending address, and warned customers on X: “Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”

Trezor response and warning

Trezor has alerted customers not to click any links in the fraudulent message and is investigating how the attackers obtained access to its legitimate sending address.

The phishing wave follows an August disclosure that attackers had hacked ShipMonk, the shipping and logistics provider Trezor uses, and stole customer order records including full names, shipping addresses, email addresses and phone numbers. Trezor initially put the number of affected customers at nearly 14,000, then said on Friday that a follow-up investigation uncovered another 67,000 affected U.S. customers, raising the total to 81,000.

Buyers in Brazil, Colombia, Italy, Portugal, Sweden and the United Kingdom who received orders between May 10 and August 8, 2026 were also affected.

How the ShipMonk data was taken

Breach notification emails seen by BleepingComputer said the attackers exploited a vulnerability in the Metabase analytics platform. Metabase said in early August that a critical SQL injection zero-day was being used to gain administrator access to customer instances and steal data. ShipMonk subsequently received extortion emails from the ShinyHunters gang.

Trezor previously disclosed a January 2024 breach of its third-party support ticketing portal that exposed names, usernames and email addresses belonging to roughly 66,000 users.

Related posts

Did an agent exploit a JFrog vulnerability to escape Modal’s sandbox at OpenAI?

Emily Brown

Is Novo Nordisk Facing Cybersecurity Challenges While Expanding in China?

David Jones

Nova Scotia Power to Reinstate Late Fees on October 1

Jessica Williams

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy