Trezor warns of email breach and phishing attacks

Published September 10, 2026

Trezor users should watch for fake emails and messages from attackers who stole data from Trezor's email provider. The attackers are sending scams that look like they come from Trezor to trick users into giving away their login details.

Report priority
Medium

How it works

  • Attackers broke into Trezor's email provider and stole customer data.
  • They now send fake Trezor emails and messages to trick users into clicking links or entering their login details.
  • These fake messages look real but lead to scam sites that steal passwords or install malware.

What to do

If you got an email or message from Trezor after June 20, 2024, check if it looks suspicious, like odd spelling, fake links, or urgent requests for your password or recovery phrase. If you clicked any links or entered details, change your Trezor password and recovery phrase immediately.

check the installed version. If you used a password or recovery phrase in any fake Trezor message, reset your Trezor password and recovery phrase right away. Trezor will send a separate email with next steps if you were directly affected.

Technical details

Attackers send fake Trezor emails with links to a fake login page. When users enter their Trezor password or recovery phrase, the attackers steal it and can take control of their crypto wallets.

Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks.