Trezor investigates phishing sent through its official email domain

Trezor said a breach at its third-party email provider allowed attackers to send phishing messages through an official company domain. The hardware-wallet maker identified the campaign on September 9, making the incident particularly notable because the messages could appear more credible than scams using lookalike sender addresses.
Trezor said a breach at its third-party email provider allowed attackers to send phishing messages through an official company domain. The hardware-wallet maker identified the campaign on September 9, making the incident particularly notable because the messages could appear more credible than scams using lookalike sender addresses.
The emails claimed that a critical hardware issue required customers to update their devices. Trezor said the messages were fraudulent, took down the affected domain, and began investigating how it had been used. The alleged vulnerability described by the scammers was part of their message, not a confirmed company finding.
The incident concerns the infrastructure used to contact customers. That is distinct from evidence that a hardware wallet itself has been compromised. A legitimate-looking email can still direct recipients toward harmful actions, making control of a trusted communication channel valuable to an attacker seeking to impersonate support staff.
Trezor's investigation adds attention to service providers around wallet manufacturers, including the systems used for customer communications. The company had also disclosed a separate shipping-provider data breach. The latest event shows how third-party relationships can create exposure even when the product's core purpose is to keep signing credentials offline.