Back to all lessons
Awareness Lessons
last month

Third-Party Email Provider Breach Enables Trezor Phishing Campaign

Trezor's customers were put at risk not through a direct compromise of Trezor itself, but through a breach of a trusted third-party email provider — a classic supply chain attack vector. Threat actors leveraged stolen contact data to craft convincing, targeted phishing emails impersonating Trezor's security alerts. This incident is compounded by a prior breach at Trezor's shipping partner ShipMonk, demonstrating that vendor risk can cascade across multiple providers and touchpoints. When organizations grant third parties access to sensitive customer data, each vendor becomes an extension of the organization's attack surface. Users who are unaware of phishing tactics are the final, critical vulnerability in this chain.

Tactical Insight

Immediate actions

  • Notify all affected customers immediately with clear guidance on how to identify and avoid the active phishing campaign.
  • Revoke or rotate any API keys, credentials, or data-sharing agreements with the compromised email provider until a full audit is complete.
  • Publish an official incident advisory on verified channels (website, verified social media) so customers can cross-check communications.

Vendor & Supply Chain controls

  • Conduct mandatory security assessments and SOC 2/ISO 27001 reviews for all third-party vendors that handle customer PII or communications.
  • Apply the principle of data minimization — share only the customer fields strictly necessary for each vendor's function.
  • Include breach notification SLAs and liability clauses in all third-party contracts to ensure timely disclosure.

Long-term user protection measures

  • Implement DMARC, DKIM, and SPF policies on all sending domains to reduce spoofed email success rates.
  • Educate customers regularly on how Trezor will (and will never) contact them, using in-product messaging and verified newsletters.
  • Establish a clear, publicized process for customers to report suspected phishing, enabling faster threat intelligence collection.