A compromised Trezor wallet email list was used to send fake data breach notifications, aiming to steal cryptocurrency wallets and the assets stored in them.
See also: Amazon: Phishing email threatens to permanently block accounts

Trezor is a hardwarethat allows you to store crypto assets offline, instead of using cloud-based wallets or wallets stored on your computer, which are more vulnerable to theft.
When setting up a new Trezor wallet, a 12 to 24 word recovery seed will be displayed that allows owners to recover their wallets if their device is stolen or lost.
However, anyone who knows this recovery seed can gain access to your wallet and stored cryptocurrencies, making it vital to store the recovery seed in a safe place.
In the ongoing attack, several Trezor users were contacted by unauthorized hackers impersonating the company, with the intent of stealing funds by misleading unwary investors. As part of the attack, users received an email about downloading an application from the domain “trezor.us”, which is different from the official Trezor domain name, “trezor.io”.
Owners of Trezor hardware wallets began receiving data breach notifications urging recipients to download a fake Trezor Suite that had the ability to steal recovery seeds.
See also: Cisco bug allows hackers to "crash" Cisco Secure Email gateways

The company confirmed on Twitter that these emails were a phishing sent through one of its newsletter opt-in forms hosted on MailChimp.
Trezor later said that MailChimp had reportedly confirmed that its service had been compromised by an “insider” targeting cryptocurrency companies. The phishing attack began with Trezor hardware wallet owners receiving fake security incident emails claiming to be a data breach notification.
These fake emails say that the company is unaware of the extent of the breach and that owners need to download the latest Trezor Suite to set a new PIN on their wallet.
The email includes a “Download Latest Version” button that takes the recipient to a phishing website that appears in the browser as suite.trezor.com.
See also: About half of emails sent in 2021 were spam
However, the website is a domain name that uses Punycode and allows attackers to mimic the domain trezor.com using accented or Cyrillic characters, with the actual domain name being suite.xn--trzor-o51b[.]com.
It should be noted that Trezor's official website is trezor.io.
