Trezor phone call and scam website

Hi all
I just wanted to let everyone know of a phone call i just got from “trezor”. It was quite convincing so I figured I’d share my experience here for others.

I got a phone call from an Unknown number, I picked up and this lovely lady with a British accent tells me that someone tried to reset my recovery from Netherlands. The first red flag was I dont recall giving trezor my phone number. Then she asked if I have any family there or anyone I know that might be able to do this. Then she went on to prove that she’s legit by first asking me to check the Trezor support page, Scams & Phishing section to see the legit domains and explaining to me how to verify everything is legit and then she sent me an email to confirm the email they had on file was correct. The email had the following subject “Not recognized - Screen issue - Ticket ID: 41963”. While scrolling through the Scams & Phishing page I noticed it said Trezor doesn’t do phone calls so that was the second red flag. Then she pretended to do some back and forth with the security team to find what the next steps should be to secure my trezor. After that she asked me to visit trezorsuitecheck dot com and Bitdefender popped up saying something fishy so that was the third red flag. On this website that looks legit it can somehow do a wireless connection with my trezor device to see whats wrong which is weird because I have an old ass trezor that doesn’t have any wifi in it. It said there was a firmware corruption and the next page was to reset the pass phrases. Thankfully my baby started screaming at that time and I used that excuse to get off the phone.

So that’s how it went down. It would have been nice if HAL agent would let me connect to an actual human so I could confirm all this but I got frustrated using it and came here to report this. If I’m wrong I’m sure someone will correct me otherwise I hope this post helps someone else out there.

Stay safe y’all

2 Likes

Hi @duperstar

there is indeed a ticket in our system with # 41963 (opened 6 hours ago) however from what I can tell someone has accessed your email and written this ticket in your name and from your email (the email address of the ticket is the same as the one you are registered here) in order to make it look like you contacted actual Trezor support.

This is most likely how they found out your phone number too which is somewhere in your mailbox.

At the moment:

  1. Immediately secure your email with a new password as someone clearly has access to it.
    2. Never share your recovery seed with anyone ever and never enter it anywhere online.

We will reply with the same response as this to the ticket, so you should see it in your email.

1 Like

So when you say secure my email with a new password, do you mean the email and password used in some trezor registration or do you mean my actual Gmail password needs to be changed?

Interestingly enough, if you’ve replied to that ticket I have yet to get an email regarding it :thinking:

Yes, your actual email.

Check again, and check your spam folder, but if someone is trying to keep this going and they have access to your email they could have deleted it.