Fake security alerts target hardware wallet users

Trezor and BitBox are warning users to disregard fraudulent security alerts, with Trezor now confirming the emails stem from a compromised third-party email service. The incident follows a recent data breach at logistics partner ShipMonk that exposed customer details and triggered extortion demands from the ShinyHunters group.
BleepingComputer reports that Trezor has confirmed the phishing emails originated from a breach of its third-party email provider, a domain the company has since taken offline. The outlet also revealed that the ShinyHunters extortion gang has contacted Trezor’s logistics partner, ShipMonk, following a separate data leak involving 81,000 customers.
Source: BleepingComputerTrezor and BitBox issued urgent warnings about fraudulent emails disguised as critical security notices, urging users to ignore links and verify communications through official channels.
Source: GN technics/hardware (en-US)






