Blockstream Green warned its users about phishing attack. The hackers will send emails that Blockstream Jade users should update their firmware. It was a fake email coming from hackers.
Are they sure that no data like email of their customers that bought the hardware wallet device directly from Blockstream website was not leaked?
How were the hackers targeting users email?
It could be without a data breach as well. Because sometimes I receive some emails where I haven't registered ever. So this would happen from other platforms' data breaches as well. From the breached data some users might use their wallet, so they might be confused by that kind of email. However, even if a data breach happened on the Blockstream website, they might try to hide it. But it's good to see they warned their users about fake emails.
Whatever the reason, we should always update from the website or from the official sources like the Play Store. Even if I receive mail from Ledger, I don't bother to click there. Instead, I visit the office website, not even from a Google search. Then try to update the wallet software.