Trezor Announces Expansion of Data Breach Impacting Approximately 67,000 U.S. Customers
Trezor, a leading cryptocurrency hardware wallet provider, announced on September 4 that approximately 67,000 U.S. customers were affected by a data breach involving its shipping partner, ShipMonk.
Two days ago, we received an update from our shipping partner, ShipMonk. It is unfortunate to inform you that more customers have been affected by the recent data leak than initially anticipated. Customers who placed orders between November 2019 and August 2021 are impacted...
Initially, the damage was thought to be limited, but it was revealed that past order data had not been deleted as expected, leading to an expansion of the affected customer base to over 80,000.
Past Data That Should Have Been Deleted Remains, Expanding the Scope of Damage
The issue became apparent in August when unauthorized access to ShipMonk's system resulted in the leak of Trezor customer personal information. Initially, Trezor reported that 13,689 customers were affected and explained that the damage was limited due to operations that delete or anonymize data within 90 days of shipping.
However, on September 2, additional information from ShipMonk revealed that order data from November 2019 to August 2021 had also been leaked. This resulted in approximately 67,000 new U.S. customers being affected, with names, email addresses, phone numbers, shipping addresses, and order numbers being compromised.
Trezor stated that it had repeatedly confirmed in writing that old order data was deleted based on its contract and data policy with ShipMonk. Nevertheless, the company expressed strong disappointment that data had actually remained.
The background to the significant expansion of the damage lies in the fact that past order data, which had been confirmed as deleted, was actually left in ShipMonk's system.
Wallets Are Safe, Caution Against Phishing and Impersonation
On the other hand, Trezor emphasized that the breach occurred on ShipMonk's system and that its own systems and Trezor devices were not affected.
However, the company warned that leaked names, addresses, and contact information could be used for phishing scams and social engineering. Attackers may impersonate Trezor, financial institutions, or cryptocurrency exchanges, reaching out via email, phone, or mail.
Trezor has already notified affected customers directly via email, urging them not to enter their wallet backup information on websites or share it with third parties. The company also cautioned about potential physical security risks arising from the leaked address information.
In response to this incident, Trezor plans to conduct additional audits of its shipping partners and implement anonymous shipping to reduce the sharing of customer information.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Houthi Forces Take Control of Mocha Port, Increasing Risks for Red Sea Shipping

WalletConnect Reports Global Crypto Regulation Enters Implementation Phase, DeFi as the Largest Unresolved Area

Anthropic Confirms Claude Model Cybersecurity Incident, Reveals Bias Reasoning and Recklessness Issues

DeepSeek Offers Direct Contact Channels for 2000 GPUs

Samsung Electronics Develops AI Glasses with Display, Expected to Launch in Second Half of 2027

UBS CEO Warns Investors Against Complacency as Risks Continue to Accumulate

Fake Security Email Targets Trezor Users

Bitcoin's Net Realized Profit Turns Positive at $176.5 Million

Clarification Needed on Licensing and Scope of Financial Companies and Virtual Asset Operators

Chinese AI Chipmakers Raise Prices Due to HBM Shortage

South Korean court rules Ethereum is an information network

South Korea parliamentary audit likely to pass without major crypto issues

Qianwen Unveils New AI Glasses N1 with Iris Payment Feature, Pricing Expected to be Lower than S1

Coinbase CEO Says Clarity Act Vote Results Will Benefit the Crypto Industry

Zamanat Launches $100 Million Tokenized Fund for GCC SMEs

U.S. Secretary Urges Quick Progress on Crypto Bill in Senate

India Promotes BRICS Nations to Use Central Bank Digital Currencies for Payments

Goldman Sachs: Japan's Pension Fund Increasing Allocation to Domestic Bonds May Trigger Yen Appreciation Impacting Asian Currency Markets

Apple Discontinues iPhone 17 Pro and Raises Prices on Several Models

Morgan Stanley's Wilson Predicts Continued Bull Market for U.S. Stocks

Fixed Term: Which Bank Offers the Most for Investing $500,000

Apple Imposes Daily Limits on AI Features in macOS 27

Nvidia and Groq Deal Under Antitrust Investigation by U.S. Justice Department

Over 50 BTC Rescued from COLDCARD Vulnerability Wallet, Transferred to Crypto Recovery Trust

Bithumb Warns Against Fake AI Trading Malware

BonkGuy: Market Pullback is a Buying Opportunity

U.S. Treasury Announces $6 Billion Buyback, 10-Year Yield Rises to 4.85%

1inch Routes $800 Billion in Trades but Still No Profit

Solana Adds 20 Tokenized Stocks Including Nike and Micron





