Trezor warned customers that attackers who breached its third-party email provider are sending phishing emails impersonating a βCritical Security Alertβ about a fake STM32 hardware vulnerability. The company is also investigating prior data breaches tied to ShipMonk and its support portal, which exposed customer order and contact information to tens of thousands of users. #Trezor #ShipMonk #STM32 #Metabase #ShinyHunters
Keypoints
- Trezor said its third-party email provider was breached.
- Attackers sent fake security alert emails to customers.
- The phishing message referenced a bogus STM32 microcontroller vulnerability.
- Trezor took down the domain and is investigating the incident.
- The company previously disclosed breaches involving ShipMonk and its support portal.