[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CYBER WATCH / Phishing & malware

Trezor warns of phishing after an email-provider breach

Trezor warned that a third-party email-provider breach was being used to send fraudulent security alerts to customers, according to BleepingComputer. The company said the messages were phishing attempts and that it was investigating. The messages' claimed wallet vulnerability is part of the lure, not a verified finding.

All updates
Reported ReportedPublished 25 September 2026

Incident timing: Customer warning issued September 9, 2026; exact compromise date not specified.

What is known

BleepingComputer reports that Trezor warned customers about fraudulent security-alert emails following a breach of its third-party email provider. The company said the messages were not genuine and advised recipients not to follow their links.

What this does not establish

The phishing message's claim about a hardware vulnerability should not be repeated as a confirmed technical issue. The report describes an investigation into misuse of an email channel, not proof that customers' hardware wallets were compromised.

Business context

Trusted communication infrastructure can become a route for impersonation after a vendor breach. This episode is separate from earlier incidents involving other Trezor service providers. The investigation was ongoing at the time of the cited report.

Source & attribution

Read the original reporting at BleepingComputer

AI-assisted summary prepared for Castler editorial review. Evidence labels describe the source of a claim, not a guarantee that every detail of an investigation is settled.

Editorial policy & corrections