Trezor said its third-party email service provider was compromised, leading to a phishing email campaign disguised as an official security alert. The email, titled "Critical Security Alert: STM32 Entropy Vulnerability," used a forged sender address, help@trezor.io. Trezor said the message was not official communication, warned users not to click links in the email, and said the related malicious domain has been taken down. The incident remains under investigation.