
Phishing Campaign Targets Crypto Users Through Compromised Email Infrastructure
Trezor, BitBox and CoinTracking warned customers Thursday that attackers had used compromised mailing infrastructure to distribute phishing emails designed to steal sensitive information from cryptocurrency users.
Multiple Crypto Companies Targeted
The incident occurred on Sept. 9 and 10 and appears to have affected more than one company. BitBox said that several bitcoin-related businesses were targeted, allowing the fraudulent messages to appear similar to legitimate security notifications.
The emails reportedly used familiar company names and security-related themes to create a sense of urgency. Recipients who followed links in the messages could have been directed to fraudulent websites designed to capture account credentials or other sensitive information.
Warnings From Wallet and Tracking Services
Trezor, a hardware wallet manufacturer, and CoinTracking, a cryptocurrency portfolio-tracking service, were among the companies that alerted users to the campaign. BitBox also issued a warning after identifying the broader targeting of bitcoin companies.
Compromised mailing systems can make phishing campaigns more convincing because messages may appear to originate from trusted services or arrive through infrastructure associated with legitimate communications.
Users Urged to Verify Security Messages
Cryptocurrency users should avoid clicking links in unexpected security emails and independently visit a company’s official website or application to review account notices. Users should also verify the sender’s domain and treat requests for passwords, private keys or wallet recovery phrases as fraudulent.
Hardware wallet providers do not need a customer’s recovery phrase to provide support. Anyone who has entered sensitive information into a suspicious website should secure affected accounts and contact the relevant service through official channels.