Trezor Breach Balloons Dramatically, Adding 67,000 More Customers To Exposure Count

Trezor Breach Balloons Dramatically, Adding 67,000 More Customers To Exposure Count
Table of Contents

TL;DR

  • Trezor revealed that a breach at its logistics provider ShipMonk exposed the personal data of another 67,000 customers in the U.S.
  • The total number of affected users now exceeds 80,000; the records date from between November 2019 and August 2021.
  • The company states that its own systems were not compromised and that private keys and wallet backups remain secure.

The hardware wallet manufacturer Trezor revealed that a security breach at ShipMonk, its external logistics provider, is considerably more serious than initially reported.

According to an official update, another 67,000 customers located in the United States had their personal information exposed, including names, email addresses, phone numbers, and shipping addresses. The affected orders correspond to the period between November 2019 and August 2021, meaning some of the compromised records were nearly seven years old.

The incident far exceeds the scope the company had communicated last month, when it reported that the breach affected approximately 13,689 customers. Of that initial group, 12,742 had their full contact and shipping data exposed, while another 1,947 experienced a more limited exposure. Adding the 67,000 newly identified cases, the total number of affected users rises to more than 80,000.

Trezor Had Asked ShipMonk to Delete the Data

One of the most concerning aspects of the case is that Trezor claims to have repeatedly requested, and received written confirmations from ShipMonk, guaranteeing that the data had been deleted in accordance with the contract and the data protection policy. “We are very disappointed that, despite having received that confirmation, the data was not deleted from their systems,” the company stated in its public update.

trezor wallet

Trezor clarified that all newly identified customers were contacted directly by email and that users who did not receive a notification are not considered affected. Its own internal systems were not compromised, and private keys along with wallet backups remain intact.

The Real Risk: Social Engineering and Physical Security

The real danger for those affected lies in the fact that criminals could use the leaked information to identify hardware wallet owners and carry out targeted attacks.

Trezor warned exposed users about phishing emails, fraudulent phone calls, and deceptive physical mail. The company also highlighted the risks to physical security, a threat that has become increasingly common among crypto users.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews