Trezor称其电子邮件提供商遭黑客入侵,钓鱼邮件通过其真实域名发送
Updated — view changes (3)
· body · New information from a source
Trezor said a third-party breach of its email provider enabled attackers to send phishing messages from what appeared to be legitimate Trezor domains, according to The Block.The fake alerts claimed a hardware flaw could expose users' recovery phrases.The breach follows a separate incident at shipping provider ShipMonk last month that exposed personal information of Trezor customers, The Block reported.- Trezor said hackers breached its third-party email provider and used the access to send phishing emails from the company's legitimate domain, according to Decrypt and The Block.
- The fraudulent messages claimed a hardware flaw in Trezor devices could expose users' recovery phrases, according to Decrypt.
- Because the emails originated from Trezor's real domain, they could appear authentic to recipients.
- The Block reported that Trezor confirmed the breach originated with a third-party provider and noted the incident follows an earlier security breach at shipping provider ShipMonk, which exposed the personal information of Trezor customers.
- Recovery phrases are used to restore access to crypto wallets, and phishing attempts that target them are a common vector for draining funds.
- Neither Decrypt nor The Block reported that any user funds were lost as a result of the phishing emails.
· summary · New information from a source
Hackers breached Trezor's email provider and sent fake security alerts claiming hardware flaws could expose user recovery phrases.- Trezor says attackers compromised its email provider and sent phishing messages from the company's real domain, falsely warning of a hardware flaw that could expose users' recovery phrases.
· headline · New information from a source
Trezor hardware wallet maker hit by email provider breach, phishing campaign launched- Trezor Says Email Provider Was Breached, Enabling Phishing Emails Sent From Its Legitimate Domain
Every change made to this story after publication is recorded here automatically. A factual error gets a correction as well, on the corrections page.
据Decrypt和The Block报道,Trezor称黑客入侵了其第三方电子邮件提供商,并利用该访问权限从该公司的真实域名发送钓鱼邮件。
据Decrypt报道,欺诈邮件声称Trezor设备存在硬件缺陷可能导致用户恢复短语泄露。由于这些邮件来自Trezor的真实域名,对收件人来说可能显得真实可信。
The Block报道称Trezor确认此次破坏源自第三方提供商,并指出该事件继承运商ShipMonk之前的安全破坏之后发生,该破坏曾泄露Trezor客户的个人信息。
恢复短语用于恢复对加密钱包的访问权限,针对其进行的钓鱼尝试是资金被抽干的常见手段。Decrypt和The Block均未报道因这些钓鱼邮件导致任何用户资金丧失。
本文仅供参考,不构成财务建议。
市场作何反应
每个数字都是本站自己的读数,并附上其比较基准。空白表示无人取得该读数,而非零。标题之前的时间窗会显示随机一小时跨过同一门槛的比例,因为没有零假设的命中率不构成结论。
事件回顾 2 条更新
- 快讯Trezor hardware wallet maker hit by email provider breach, phishing campaign launched首次报道 · 2 个来源decrypt.co · theblock.co
- 报道Trezor Says Email Provider Was Breached, Enabling Phishing Emails Sent From Its Legitimate Domain更新 · 2 个来源decrypt.co · theblock.co
Cite this
Archived copy · an independent capture of this page at the Internet Archive, kept so this report can be checked against what it said on the day
← 更多 Byte