ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Website Virus Removal
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Supply Chain Phishing: When Your Email Provider Becomes the Attack Vector

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Supply Chain Phishing: When Your Email Provid...
  • All articles
  • Categories
  • Tags
  • Statuses

Supply Chain Phishing: When Your Email Provider Becomes the Attack Vector

The Trezor incident: a wake-up call for third-party riskWhen a hardware wallet manufacturer like Trezor discloses that attackers breached an external...

The Trezor incident: a wake-up call for third-party risk

When a hardware wallet manufacturer like Trezor discloses that attackers breached an external email provider to send phishing messages, the story is not just about cryptocurrency. It is a textbook example of supply chain risk that affects any organisation relying on third-party services — including hosting companies, system administrators and SMEs with their own servers in Barcelona, Lleida, Tarragona or Girona.

Cracked padlock replacing a chain link, symbolising a third-party breach in the supply chain

According to reports, attackers gained access to an email service used by Trezor for customer communications. They then sent messages with the subject line "Critical Security Alert: STM32 Entropy Vulnerability", pretending to be official support. The email claimed a hardware flaw in STM32 microcontrollers would reduce entropy and allow seed phrase reconstruction. No CVE supports that claim, and the pattern fits the classic brand impersonation playbook: fear, urgency and a link to a credential-harvesting site.

Trezor has since disabled the domain used in the campaign and continues to investigate. The incident highlights a recurring problem: when an attack originates in a third party, such as an email marketing provider or a shared mail service, the attacker can send messages that bypass normal filters and appear as part of the brand's regular flow.

Why supply chain phishing is so effective

The campaign also benefited from context. Recent alerts about entropy generation issues in products from other manufacturers made a technical warning seem plausible. This informational noise lowers our guard.

Security researchers have noted signs that similar emails may have reached users of BitBox, suggesting a possible pattern of compromise in providers shared by several companies in the ecosystem. For IT teams, the lesson is clear: your security posture is only as strong as your weakest supplier.

In Spain, where GDPR imposes strict obligations on data processors, a breach at a provider can quickly become your problem. Article 28 of the GDPR requires written contracts with processors, but technical controls are equally important.

Practical steps to reduce third-party risk

  • Map your suppliers: list every external service that touches customer data or email. Include marketing platforms, CRM, helpdesk and cloud providers.
  • Demand transparency: ask for their incident response plans and breach notification timelines.
  • Segment access: use dedicated domains and subdomains for different services so a compromise in one does not affect the others.
  • Monitor reputation: watch for sudden changes in sending IP reputation or domain blacklisting.
  • Train your team: run phishing simulations that include fake technical alerts, not just generic invoices.

For system administrators, the email provider is just one entry point. The servers themselves need active defence. This is where a tool like Abuse Shield from ALMC becomes relevant. It centralises protection across your servers: automatic blocking of malicious IPs, managed fail2ban on multiple machines, and a shared reputation feed between all your servers. If one server detects an attack, the others learn from it instantly.

Hardening your own infrastructure

While you cannot control your provider's security, you can control your servers. Here are key measures:

  • Deploy fail2ban everywhere: it is not enough on one server. Attackers often probe multiple machines. Managed fail2ban across your fleet ensures consistent rules.
  • Use a shared IP reputation feed: when one server blocks an IP, that information should propagate. Abuse Shield does this automatically, reducing the window of exposure.
  • Enforce DMARC, DKIM and SPF: these email authentication protocols help prevent your domain from being spoofed in phishing campaigns.
  • Apply the principle of least privilege: limit who can access email marketing tools and customer databases.
  • Monitor outbound traffic: a compromised server may start sending spam. Early detection prevents blacklisting.

In Catalonia, where many SMEs run their own servers or use local hosting, these practices are not optional. A phishing campaign that impersonates your brand can destroy customer trust faster than any technical failure.

Incident response: what to do when a third party is breached

If you learn that a provider has been compromised, act as if your own systems were breached. Revoke API keys and tokens shared with that provider. Force password resets for affected accounts. Inform your customers transparently, especially if their data may be at risk. Under GDPR, you may need to notify the Spanish Data Protection Agency (AEPD) within 72 hours if the breach poses a risk to individuals' rights and freedoms.

For security teams, this incident reinforces the need for playbooks that cover third-party failures and more aggressive anti-phishing controls: domain filtering, URL analysis and rules that detect recurring subject lines and text from campaigns like this one.

Finally, remember the golden rule: no legitimate service will ever ask for your seed phrase, password or private key by email. If an unsolicited message demands urgent action, do not click links or download attachments. Verify the alert through official channels. If you have already entered credentials, assume compromise, revoke access and move funds only through verified procedures from official interfaces.

Supply chain attacks are here to stay. The best defence is a combination of supplier diligence, employee awareness and robust server-level protection. With tools like Abuse Shield, you can at least ensure that your own infrastructure is not the weak link.

Related

  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
  • Fail2ban: Your First Line of Defense Against Unauthorized Server Access
  • Critical libssh2 flaw: urgent patch for SSH servers
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Full Stack Web Development Laravel, Vue.js
System & Server Hardening
Security Audits and Pentesting
Virtualization & Containers (Docker, Kubernetes)
Server Management & Monitoring
Relacionados
  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
    Cybersecurity · 2 days ago
  • Critical libssh2 flaw: urgent patch for SSH servers
    Cybersecurity · 2 days ago
  • Fail2ban: Your First Line of Defense Against Unauthorized Server Access
    Cybersecurity · 2 days ago
  • FortiBleed: Guarding Your Perimeter Against Credential Harvesting
    Cybersecurity · 2 days ago
  • Browser Extensions: A Hidden Supply-Chain Risk for Your Servers
    Cybersecurity · 2 days ago
  • Critical LoadMaster RCE: What Sysadmins Must Do Now
    Cybersecurity · 2 days ago
Servidores MCP Destacados
  • MCP Read Images
    Development
  • MCP Server Executable
    Development
  • Rootly
    Productivity
  • Cloudflare Remote MCP Server (Authless)
    Cloud Service
  • RentCast
    Database
  • Fast.io
    Cloud Storage
  • APOGEOAPI
    Cloud Service
  • Higress AI-Search MCP Server
    Search
  • HeyBeauty
    Development
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-11
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar