INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Trezor Warns Users of Email Provider Breach and Phishing Attacks

| 2026-09-10 06:56 CRITICAL LOW DATA BREACH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
On September 10, 2026, cryptocurrency hardware wallet maker Trezor warned customers of a phishing attack and data breach that targeted nearly 81,000 users in the United States, Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom. The attackers exploited a vulnerability in ShipMonk's Metabase analytics platform to gain administrator access and steal customer order data between May 10 and August 8, 2026. Trezor stated that it had taken down its third-party email provider domain to stop phishing attacks targeting customers with fake "Critical Security Alert" emails claiming a hardware microcontroller vulnerability in STM32 microcontrollers could expose their seeds to brute-force cracking.
Technical Mitigations AI-generated
• Block phishing emails from <a href="/auth/login?next=/detail/cPfQiqABGvYhsJJTdDnT" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a> and any other suspicious email addresses. • Use a secure password manager to generate strong, unique passwords for Trezor accounts. • Regularly update the Metabase analytics platform to patch the critical SQL injection zero-day vulnerability.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

he•••@tr•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA NORTH_AMERICA NORDICS NORDICS cryptocurrencycryptocurrency logisticslogistics
Incident Timeline
‎January 2024
Trezor disclosed a data breach after its third-party support ticketing portal was compromised, exposing approximately 66,000 users' names, usernames, and email addresses.
tactic Data Breach
victims 66,000 users
organisation The Blue Report 2026
‎August 8, 2026
Threat actors exploited a critical SQL injection zero-day vulnerability in the Metabase analytics platform to breach customer instances and steal data.
threat_actor ShinyHunters
organisation BleepingComputer
organisation Metabase
organisation SQL
‎between May 10 and August 8, 2026
Threat actors used phishing attacks to target customers of an email provider who received orders between May 10 and August 8, 2026.
target_region Brazil
target_region Colombia
target_region Italy
target_region Portugal
target_region Sweden
target_region United Kingdom
tactic Data Breach
‎2026/09/10
Threat actors who breached Trezor's third-party email provider are targeting users in phishing attacks.
organisation Trezor
organisation ShipMonk
organisation STM32
victims 14,000 customers
victims 67,000 additional U.S. customers
Tactical Metrics
Metrics
victims
66,000
Users
Metrics
victims
14,000
Customers
Metrics
victims
67,000
Additional U.S. Customers
Intelligence Sources
BleepingComputer 2026-09-10