"Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain."
Their devices have never been [known to be] remotely breached, but still…
2022: Their Mailchimp account breached
2024: Their support ticket portal breached
2025: Support contact form sent phishing via official auto-replies
Aug 2026: Shipping partner ShipMonk breached
Sep 2026: Email provider breached
Anything Trezor knows about you should be considered thoroughly compromised.
B2B SaaS doesn't have the level of security that crypto needs.
https://archive.today/H4hbC
"Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.
We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain."