TREE NEWS update: Trezor said a third-party security breach allowed attackers to send phishing emails from its legitimate domain, following last month’s hack at shipping provider ShipMonk that exposed customers’ personal information. The hardware wallet maker disclosed the incident as users face follow-on phishing attempts tied to the leaked data.
Trezor Says Third-Party Breach Let Attackers Send Phishing Emails From Its Domain
The notable detail is not the phishing itself but the vector: attackers abused a trusted domain rather than spoofing one, which defeats the domain-based trust signals users are taught to rely on. The ShipMonk leak supplied the targeting data, so the two incidents compound — a hardware wallet's core pitch rests on users never exposing keys, yet the attack surface here is email and personal data, outside the device entirely. Whether other ShipMonk clients see the same follow-on activity is the open question.
Generated by AI for reference only.
Share on WeChat
Open WeChat → Scan → then tap "…" to send to a chat or Moments.
Tap "…" in the top-right corner to send to a chat or share to Moments.