Trezor says mailing breach leaked 67,000 more users than first thought
Trezor breach scope expands to over 80,000 users
Crypto hardware wallet maker Trezor has revealed that a data breach involving its shipping partner was much larger than first believed. On September 4, the company said another 67,000 US users were affected, bringing the total number of impacted customers to over 80,000.
Trezor first disclosed the incident last month after bad actors infiltrated the systems of ShipMonk, the mailing company Trezor uses for deliveries. At that time, the firm said the personal details of 13,689 customers had been leaked. It initially downplayed the scale of the problem by pointing to a 90-day data policy, which says partners should delete old user data.
That explanation no longer holds. Trezor now claims ShipMonk never enforced the deletion policy and kept the data. “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data,” the company said.
Trezor apologized to those affected. It said it is working to ship “anonymous delivery” soon, allowing customers to place orders without exposing their personal information.
Key numbers on the breach
- Initial leak reported last month: 13,689 US customers.
- Newly disclosed leak: 67,000 additional US customers.
- Total affected: over 80,000 users.
- Data scope: ShipMonk informed Trezor on September 2 that the leak actually extends back to 2019 and 2021.
Why the second disclosure came weeks later
Trezor told Protos that it did not expect further leaks because of ShipMonk’s repeated assurances. The company said ShipMonk made it aware of the initial leak on August 10, covering only orders from the previous 90 days. ShipMonk only revealed the broader scope on September 2.
Trezor stated that cooperation from earlier years was overlooked when the original scope of the breach was established. The firm said it had “no reason to expect it” that more data would be compromised.
Unlike the initial disclosure, Trezor chose not to reach out to Protos for this update. When asked why, the company said the information is public and not behind any paywall, adding that its priority was reaching the people actually affected.
What could happen next
Trezor said it is too early to decide what action it will take in response to ShipMonk’s handling of the breach. However, the company confirmed it is working to arrange an additional audit of the mailing partner.
Breaches of this kind can make crypto users targets for criminals, who may use the leaked personal information to tailor phishing attacks or other scams.