تريزور تقول إن موفر بريدها الإلكتروني تعرض للاختراق، مما أتاح إرسال رسائل التصيد الاحتيالي من نطاقها الشرعي
Updated — view changes (3)
· body · New information from a source
Trezor said a third-party breach of its email provider enabled attackers to send phishing messages from what appeared to be legitimate Trezor domains, according to The Block.The fake alerts claimed a hardware flaw could expose users' recovery phrases.The breach follows a separate incident at shipping provider ShipMonk last month that exposed personal information of Trezor customers, The Block reported.- Trezor said hackers breached its third-party email provider and used the access to send phishing emails from the company's legitimate domain, according to Decrypt and The Block.
- The fraudulent messages claimed a hardware flaw in Trezor devices could expose users' recovery phrases, according to Decrypt.
- Because the emails originated from Trezor's real domain, they could appear authentic to recipients.
- The Block reported that Trezor confirmed the breach originated with a third-party provider and noted the incident follows an earlier security breach at shipping provider ShipMonk, which exposed the personal information of Trezor customers.
- Recovery phrases are used to restore access to crypto wallets, and phishing attempts that target them are a common vector for draining funds.
- Neither Decrypt nor The Block reported that any user funds were lost as a result of the phishing emails.
· summary · New information from a source
Hackers breached Trezor's email provider and sent fake security alerts claiming hardware flaws could expose user recovery phrases.- Trezor says attackers compromised its email provider and sent phishing messages from the company's real domain, falsely warning of a hardware flaw that could expose users' recovery phrases.
· headline · New information from a source
Trezor hardware wallet maker hit by email provider breach, phishing campaign launched- Trezor Says Email Provider Was Breached, Enabling Phishing Emails Sent From Its Legitimate Domain
Every change made to this story after publication is recorded here automatically. A factual error gets a correction as well, on the corrections page.
قالت تريزور إن المتسللين اخترقوا موفر بريدها الإلكتروني من جهة خارجية واستخدموا الوصول لإرسال رسائل التصيد الاحتيالي من النطاق الشرعي للشركة، وفقاً لـ Decrypt و The Block.
ادعت الرسائل الاحتيالية وجود عيب في أجهزة تريزور قد يعرض العبارات الاستذكارية للمستخدمين للخطر، وفقاً لـ Decrypt. نظراً لأن رسائل البريد الإلكتروني بدأت من النطاق الحقيقي لتريزور، فقد تبدو أصلية للمستقبلين.
أفادت The Block بأن تريزور أكدت أن الاختراق نشأ من موفر خارجي، وأشارت إلى أن الحادثة تأتي بعد اختراق أمني سابق في موفر الشحن ShipMonk، الذي كشف عن المعلومات الشخصية لعملاء تريزور.
تُستخدم العبارات الاستذكارية لاستعادة الوصول إلى المحافظ الرقمية، ومحاولات التصيد الاحتيالي التي تستهدفها هي ناقل شائع لاستنزاف الأموال. لم تفيد أي من Decrypt أو The Block بأن أي أموال للمستخدمين فُقدت نتيجة رسائل التصيد الاحتيالي.
هذه المقالة لأغراض إعلامية فقط وليست نصيحة مالية.
ماذا فعل السوق
كل رقم هنا قراءة خاصة بهذا الموقع، مع ما قيس مقابله. الفراغ يعني قراءة لم يأخذها أحد، لا صفرًا. ونافذة ما قبل العنوان تعرض نسبة تجاوز ساعة عشوائية للحد نفسه، لأن نسبة إصابة بلا فرضية عدم ليست نتيجة.
مستجدات القصة 2 تحديثات
- عاجلTrezor hardware wallet maker hit by email provider breach, phishing campaign launchedأول تقرير · 2 مصادرdecrypt.co · theblock.co
- تقريرTrezor Says Email Provider Was Breached, Enabling Phishing Emails Sent From Its Legitimate Domainتحديث · 2 مصادرdecrypt.co · theblock.co
Cite this
Archived copy · an independent capture of this page at the Internet Archive, kept so this report can be checked against what it said on the day
→ المزيد من Byte