{"id":22928,"date":"2022-04-03T22:11:11","date_gmt":"2022-04-03T21:11:11","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=22928"},"modified":"2022-04-27T03:47:07","modified_gmt":"2022-04-27T07:47:07","slug":"trezor-investigates-potential-data-breach","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/trezor-investigates-potential-data-breach\/","title":{"rendered":"Trezor wallet investigates potential data breach through phishing attacks"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\"><a href=\"https:\/\/coinscreed.com\/staging\/trezor-wallet-containing-2m-worth-of-crypto-cracked-by-renowned-computer-engineer.html\" data-type=\"post\" data-id=\"17344\">Trezor,<\/a> a cryptocurrency hardware wallet company, has initiated an investigation into a probable data breach of an ongoing email phishing campaign which has been reported by various users on Twitter.<\/h5>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-3-1024x424.png\" alt=\"Trezor wallet investigates potential data breach through phishing attacks\" class=\"wp-image-22929\" width=\"891\" height=\"369\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-3-1024x424.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-3-300x124.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-3-768x318.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-3-150x62.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-3-750x310.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-3.png 1034w\" sizes=\"(max-width: 891px) 100vw, 891px\" \/><figcaption>Trezor wallet investigates potential data breach through phishing attacks<\/figcaption><\/figure><\/div>\n\n\n\n<p>On April 3, numerous members of the<a href=\"https:\/\/www.google.com\/search?q=Trezor+wallet+investigates+potential+data+breach+following+users+complaints+about+phishing+attacks&rlz=1C1SQJL_enNG889NG889&oq=Trezor+wallet+investigates+potential+data+breach+following+users+complaints+about+phishing+attacks&aqs=chrome..69i57.888j0j9&sourceid=chrome&ie=UTF-8\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=Trezor+wallet+investigates+potential+data+breach+following+users+complaints+about+phishing+attacks&rlz=1C1SQJL_enNG889NG889&oq=Trezor+wallet+investigates+potential+data+breach+following+users+complaints+about+phishing+attacks&aqs=chrome..69i57.888j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\"> <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><a href=\"https:\/\/www.google.com\/search?q=Trezor+wallet+investigates+potential+data+breach+through+phishing+attacks&rlz=1C1SQJL_enNG889NG889&oq=Trezor+wallet+investigates+potential+data+breach+through+phishing+attacks&aqs=chrome..69i57.786j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=Trezor+wallet+investigates+potential+data+breach+through+phishing+attacks&rlz=1C1SQJL_enNG889NG889&oq=Trezor+wallet+investigates+potential+data+breach+through+phishing+attacks&aqs=chrome..69i57.786j0j9&sourceid=chrome&ie=UTF-8\" rel=\"noreferrer noopener\">Crypto Twitter community<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> warned about an ongoing email phishing campaign targeting Trezor users via their registered email accounts.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Act accordingly.<\/p>&mdash; Trezor (@Trezor) <a href=\"https:\/\/twitter.com\/Trezor\/status\/1510244772425785348?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 2, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Several Trezor users have been approached by unauthorized actors posing as the company in the ongoing campaign, with the ultimate goal of stealing cash by deceiving naive investors.<\/p>\n\n\n\n<p>Users were sent an email about installing an app from the &#8216;trezor.us' domain, which is different from the official Trezor domain name, &#8216;trezor.io,' as part of the attack.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">We are investigating a potential data breach of an opt-in newsletter hosted on MailChimp.<br><br>A scam email warning of a data breach is circulating. Do not open any email originating from noreply@trezor.us, it is a phishing domain.<\/p>&mdash; Trezor (@Trezor) <a href=\"https:\/\/twitter.com\/Trezor\/status\/1510548489884815361?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 3, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Trezor first assumed the hacked email addresses belonged to a list of users who had opted-in for newsletters hosted by Mailchimp, an American email marketing service provider.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Wow, <a href=\"https:\/\/twitter.com\/Trezor?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@Trezor<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, this is the best phishing attempt I have seen in the last few years. I am really lucky I don&#39;t have Trezor, because if I had, I would probably actually download that update. <a href=\"https:\/\/t.co\/DaBN2Oix11\" target=\"_blank\">pic.twitter.com\/DaBN2Oix11<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Tom\u00e1\u0161 Kafka (@tomaskafka) <a href=\"https:\/\/twitter.com\/tomaskafka\/status\/1510400852716052480?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 2, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Trezor announced the following after additional investigation:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>&#8220;MailChimp have confirmed that their service has been compromised by an insider targeting crypto companies.&#8221;<\/p><\/blockquote>\n\n\n\n<p>While Trezor conducts an <a href=\"https:\/\/coinscreed.com\/staging\/indian-police-investigation-reveals-the-hamas-group-involvement-in-a-crypto-hack.html\" data-type=\"post\" data-id=\"17113\" target=\"_blank\" rel=\"noreferrer noopener\">official investigation<\/a> to determine the total number of stolen email addresses, users should refrain from clicking on links from unauthorized sources until further notice.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">BlockFi also warns about phishing attacks<\/h2>\n\n\n\n<p>BlockFi, a crypto-financial institution situated in <a href=\"https:\/\/coinscreed.com\/staging\/new-jersey-authorities-issue-voyager-digital-cease-and-desist-order.html\" data-type=\"post\" data-id=\"22491\" target=\"_blank\" rel=\"noreferrer noopener\">New Jersey<\/a>, proactively verified a <a href=\"https:\/\/www.idstrong.com\/data-breaches\/\" target=\"_blank\" data-type=\"URL\" data-id=\"https:\/\/www.idstrong.com\/data-breaches\/\" data-schema-attribute=\"mentions\" rel=\"noreferrer noopener\">data breach<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> on March 19 to alert investors about the risk of phishing attempts.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Regarding recent third-party data incident: <a href=\"https:\/\/t.co\/50z7IrQ1za\" target=\"_blank\">pic.twitter.com\/50z7IrQ1za<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; BlockFi (@BlockFi) <a href=\"https:\/\/twitter.com\/BlockFi\/status\/1504982848771608586?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">March 19, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Hackers acquired access to BlockFi's client data held on Hubspot, a client relationship management platform, according to reports. BlockFi claims that:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cHubspot has confirmed that an unauthorized third-party gained access to certain <a href=\"https:\/\/coinscreed.com\/staging\/sec-charges-blockfi-with-a-100-million-fine-for-failure-to-comply-with-regulatory-law.html\" target=\"_blank\" data-type=\"post\" data-id=\"18228\" rel=\"noreferrer noopener\">BlockFi <\/a>client data housed on their platform.\u201d<\/p><\/blockquote>\n\n\n\n<p>While the specifics of the data breach have yet to be uncovered, BlockFi reassured consumers by stating that personal information such as passwords, government-issued IDs, and social security numbers &#8220;were never saved on Hubspot.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Trezor, a cryptocurrency hardware wallet company, has initiated an investigation into a probable data breach of an ongoing email phishing campaign which has been reported by various users on Twitter. On April 3, numerous members of the Crypto Twitter community warned about an ongoing email phishing campaign targeting Trezor users via their registered email accounts. [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":22929,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[8624,8623,8622,482],"class_list":["post-22928","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-data-breach","tag-phishing-attacks","tag-trezor-2","tag-twitter"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/04\/image-3.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/22928","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=22928"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/22928\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/22929"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=22928"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=22928"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=22928"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}