Trezor supply chain breach exposes 81,000 customer records
Trezor has announced that a data breach at shipping partner ShipMonk compromised information from about 81,000 customers, far more than the firm initially reported. Customer names, emails, phone numbers, addresses, and order numbers from purchases between November 2019 and August 2021 were exposed. Trezor says the breach did not affect the wallets themselves. ShipMonk has secured systems since the incident. Trezor is considering legal action.
- Data breach traced to ShipMonk, Trezor's logistics partner
- Exposed data includes orders from 2019 to 2021
- Initial Trezor estimates missed 67,000 affected users
- Trezor says wallet device security is unaffected
- Trezor may take legal action against ShipMonk
Sources covering this
More in Cybersecurity
Browser-based malware campaign targets cryptocurrency users
Cisco Talos reports a criminal campaign targeting cryptocurrency traders by convincing users to paste or install malicious JavaScript in their browsers. The scheme uses Google Sheets and Docs to host and distribute the code, which then intercepts crypto transactions by modifying deposit addresses and displaying fake bonuses. Victims are lured via messages on Telegram, DarkForums, and paste sites, often under the pretext of exploiting a non-existent API vulnerability for profit.
OpenAI pledges $1 billion for AI cyber defense program
OpenAI has pledged $1 billion in credits to help organizations defending critical U.S. infrastructure—including water utilities, electric grids, local governments, banks, and nonprofits—access its AI-powered cybersecurity tools, training, and support. The "Daybreak for Frontline Defenders" initiative aims to help these sectors strengthen their defenses as AI-driven cyberattacks become more advanced. OpenAI says it will expand the program to partner countries in the coming weeks.
Malware campaign targets Ukrainian agency with credential theft
Cisco Talos reports that a Ukrainian government organization experienced a malware attack involving a DLL file executed through WebDAV. The malware chain led to the installation of credential and cryptocurrency stealers, including Amatera stealer, ZigCryptoStealer, and NetSupport Manager. The attackers, believed with moderate confidence to be Russian, used deceptive prompts to infect victims, but did not specifically target the affected organization.
Breeze Comet targets Brazilian financial firms with fraud
A group known as Breeze Comet has targeted Brazilian banks, retailers, and e-commerce companies through sophisticated attacks since early 2024, according to Google Cloud and Mandiant. The organization uses malware and voice phishing to access internal payment systems and carry out fraudulent transfers. Google states that Breeze Comet is also using generative AI to develop new malware and may expand operations to parts of Latin America and Africa.