Brother
Professional
- Messages
- 2,590
- Reaction score
- 539
- Points
- 113
Trezor hardware wallet developers have reported a security incident with a third-party support provider that resulted in a data breach for approximately 66,000 customers.
Users who interacted with the service since December 2021 were affected. The attackers obtained the names/pseudonyms and email addresses of those who contacted the service.
The Trezor team sent emails to all victims warning about possible phishing.
According to the statement, since January 17, when the attack occurred, “no significant activity” of hackers in this direction has yet been recorded. However, at least 41 users received a message from them requesting sensitive information related to the wallet's seed phrase.
Message in which the attackers asked the user for a seed phrase, allegedly to check the firmware version of his wallet
The developers emphasized that Trezor representatives “will never ask you to do this.”
According to them, no user assets were damaged as a result of the incident.
Security Alert
On January 17, 2024, the third-party support ticketing portal we use encountered unauthorized access.
Potentially impacted data are limited to user emails and names/nicknames that contacted our customer support team.
We want to assure you that this does not… pic.twitter.com/hnxBYBlvlO
— Trezor (@Trezor) January 20, 2024
Users who interacted with the service since December 2021 were affected. The attackers obtained the names/pseudonyms and email addresses of those who contacted the service.
The Trezor team sent emails to all victims warning about possible phishing.
According to the statement, since January 17, when the attack occurred, “no significant activity” of hackers in this direction has yet been recorded. However, at least 41 users received a message from them requesting sensitive information related to the wallet's seed phrase.
Message in which the attackers asked the user for a seed phrase, allegedly to check the firmware version of his wallet
The developers emphasized that Trezor representatives “will never ask you to do this.”
According to them, no user assets were damaged as a result of the incident.