2 Remove Virus

Trezor breach expands to 81,000 customers after old order records found exposed

The number of Trezor customers affected by a breach at logistics provider ShipMonk has risen to approximately 81,000 after an investigation uncovered tens of thousands of older customer records that should have been deleted.

 

 

Trezor initially disclosed the incident on August 13th, reporting that nearly 14,000 customers had been affected. The hardware wallet maker has now revealed that ShipMonk informed it on September 2nd that information belonging to another 67,000 customers in the United States was also exposed.

The newly identified group consists of people who placed Trezor orders between November 2019 and August 2021. Exposed records include names, email addresses, telephone numbers, shipping addresses, and order numbers.

The discovery is particularly significant because Trezor says this older information was not supposed to remain in ShipMonk’s systems. The company requires fulfillment partners to delete or anonymize order information 90 days after delivery.

According to Trezor, it repeatedly sought confirmation that ShipMonk had removed the information and received written assurances that deletion had taken place. The latest investigation showed that the records had instead remained stored by the logistics provider.

The original August disclosure involved more recent orders. Trezor said 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed, while another 1,947 people had a smaller set of information compromised, consisting of their names, cities and email addresses.

Trezor’s own infrastructure was not breached, and the incident does not affect the security of its hardware wallets or the cryptocurrency stored through them. However, the personal information obtained from ShipMonk could provide useful material for targeted phishing and social engineering.

Attackers could use names, contact information, purchase details and addresses to make communications impersonating Trezor appear more convincing. Customers have therefore been warned to be suspicious of unexpected emails, telephone calls and physical letters. Exposure of home addresses may also create additional physical security concerns for cryptocurrency owners.

Trezor has contacted customers included in the expanded disclosure. The company continues to emphasize that users should never disclose their wallet backup or recovery seed in response to unsolicited communications.