Trezor investigates potential data breach as users cite phishing attacks


Cryptocurrency hardware wallet provider Trezor has begun investigating a potential data breach that may have compromised users' email addresses and other personal information.

Earlier today, on April 3, several users in the Crypto Twitter community warned of an ongoing email phishing campaign specifically targeting Trezor users via their registered email addresses.

In the ongoing attack, several Trezor users have been contacted by unauthorized actors posing as the company, with the ultimate intention of stealing funds by tricking unsuspecting investors. As part of the attack, users received an email about downloading an app from the domain 'trezor.us', which is different from Trezor's official domain name 'trezor.io'.

Trezor initially suspected that the compromised email addresses belonged to a list of users who opted in to receive newsletters, which was hosted by a US email marketing service provider, Mailchimp.

While Trezor attempts to identify the root cause of the situation with an official investigation, users are advised not to click on links from unofficial sources until further notice.

Related: BlockFi Confirms Unauthorized Access to Hubspot-Hosted Customer Data

On March 19, New Jersey-based crypto-financial institution BlockFi proactively confirmed a data breach to warn investors about the possibility of phishing attacks.

As Cointelegraph reported, hackers gained access to BlockFi customer data that was hosted on Hubspot, a customer relationship management platform. According to BlockFi:

"Hubspot has confirmed that an unauthorized third party gained access to certain BlockFi customer data hosted on its platform."

While details of the breached data have yet to be identified or disclosed, BlockFi reassured users by highlighting that personal data, including passwords, government-issued IDs, and social security numbers, "was never stored in hubspot".