{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet"},"incident":{"title":"Mailchimp staff social-engineered; Trezor newsletter used to phish wallet seeds","date":"2022-04-03","date_precision":"day","victim_org":"SatoshiLabs (Trezor), via email provider Mailchimp","sector":"Cryptocurrency","country":"Czech Republic","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Credential Phishing Portal","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Data Breach","Credential Theft","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"Neither Trezor nor Mailchimp published a loss figure, and Trezor said at the time it was unclear whether any funds were successfully stolen. The '106,856 customers' figure that circulated came from the phishing email itself and was attacker-authored text, not a confirmed breach count.","records_affected":null,"threat_actor":"Unattributed actor targeting cryptocurrency-sector Mailchimp tenants","summary":"Attackers ran a social engineering attack against Mailchimp employees to reach an internal customer support tool, then used it to pull mailing lists from cryptocurrency-sector accounts including Trezor's. Phishing emails sent from a lookalike domain, noreply@trezor.us, told recipients that Trezor had suffered a breach and instructed them to install a new version of Trezor Suite. The fake application, including a convincing web version, prompted victims to connect their wallets and enter their recovery seed phrase.","how_it_worked":"The deception happened two steps upstream of the victims. Mailchimp employees were socially engineered into giving attackers access to an internal support and account-administration tool, which let the attackers view and export subscriber lists across tenant accounts and specifically target crypto companies. Holding Trezor's real newsletter list, the attackers sent a security-alert email that borrowed Trezor's own incident-response voice, from the plausible domain trezor.us. Recipients who followed the link reached a cloned Trezor Suite with working-looking functionality that asked for the recovery seed, the one secret that grants irreversible control of a hardware wallet.","lessons":"Hardware wallet vendors should state unconditionally that no update or support flow ever asks for a seed phrase, and email service providers need step-up controls and anomaly detection on internal tools that can export any tenant's subscriber list.","confidence":"Confirmed","sources":[{"title":"Ongoing phishing attacks on Trezor users","url":"https://blog.trezor.io/ongoing-phishing-attacks-on-trezor-users-edd840b17304","publisher":"Trezor (SatoshiLabs)"},{"title":"Mailchimp Insider Targets Trezor Crypto Wallets in Phishing Scam","url":"https://decrypt.co/96942/mailchimp-insider-targets-trezor-crypto-wallets-phishing-scam","publisher":"Decrypt"}],"entry_type":"incident","slug":"2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-mailchimp-staff-social-engineered-trezor-newsletter-used-to-phish-wallet"}}