pull down to refresh

The company's support site allows anyone to open a ticket using any email address and subject line. The system then replies automatically, sending a case number and using the submitted ticket title as the email subject.
Attackers abuse this feature by submitting tickets with titles containing urgent phishing messages, such as "[URGENT]: vault.trezor.guide - Create a Trezor Vault now in order to secure assets who may potentially be at risk."
Since the reply comes from the legitimate help@trezor.io address, it appears authentic to recipients but contains an email subject with a fake alert that links to a phishing site.
This is what makes me so nervous about hardware wallets in general (seedsigner and krux excepted): you are on a list.
It contains the link in the subject line? Is that even launchable in most browsers?
But still, not great
reply
Perhaps the person who is willing to believe it is willing to copy paste?
reply
That’s definitely believable. They gotta lock this shit down
reply
Curious if they managed to automate this and how, or if some scammer had to do this by hand (create each ticket)?
reply
I doubt you are on the list in this case unless asking for explicit support. And in that case, please correct me, only your email is on the list.
reply