Trezor says ShipMonk breach expanded to 67,000 additional US customers

Trezor says ShipMonk breach expanded to 67,000 additional US customers

Updated breach figures reveal broader impact

Trezor announced on Friday that a data breach involving its shipping partner, ShipMonk, affected approximately 67,000 more US customers. This expands the scope of the incident that was first disclosed last month, when the company reported nearly 14,000 affected customers.

ShipMonk informed Trezor of the larger scale on September 2. The newly identified records cover orders placed between November 2019 and August 2021. The exposed information includes customer names, emails, phone numbers, shipping addresses, and order numbers.

Concerns over deleted data

Trezor stated that it had repeatedly requested ShipMonk to delete the data throughout their business relationship. The company said it received written assurances that the information had been removed in line with its contract, data policy, and previous communications. Trezor expressed disappointment that the data remained in ShipMonk's systems despite these confirmations.

Hardware wallets remain secure

The company emphasized that its own systems were not compromised and that its hardware wallets remain secure. A hardware wallet is a physical device used to store cryptocurrency keys offline. Trezor confirmed it has emailed all customers affected by this latest disclosure.

The company warned customers to watch out for scam emails, fraudulent calls, letters, and potential physical security risks. When Trezor initially disclosed the breach on August 13, it said a policy required fulfillment partners to delete or anonymize order data 90 days after delivery.

Why exposed addresses pose risks

The exposure of home addresses goes beyond the risk of phishing scams. A 2020 breach at Ledger, another hardware wallet maker, exposed information for more than 270,000 customers. Some of that leaked data, including home addresses, was published on a hacking forum. Ledger customers have continued to report receiving scam phone calls and physical letters years later, highlighting the long-term danger of address leaks.

Original disclosure details

In its first announcement, Trezor reported that 11,742 customers had their names, emails, phone numbers, and shipping addresses exposed. Another 1,947 customers had their names, cities, and email addresses leaked.

  • ShipMonk breached data for roughly 67,000 additional US customers
  • The breach covers orders from November 2019 to August 2021
  • Trezor says it received written assurances the data was deleted previously
  • Trezor's own systems and hardware wallets were not compromised
YA
Written by

Yasir Arafat

Owner & Developer
View all posts

Yasir Arafat is a software developer and the founder of Newisty, covering web development, software, online tools and digital technology. He also oversees Newisty's publishing, technical development and editorial process.


Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!