Trezor Announces Expansion of Data Breach Impacting Approximately 67,000 U.S. Customers
Trezor, a leading cryptocurrency hardware wallet provider, announced on September 4 that approximately 67,000 U.S. customers were affected by a data breach involving its shipping partner, ShipMonk.
Two days ago, we received an update from our shipping partner, ShipMonk. It is unfortunate to inform you that more customers have been affected by the recent data leak than initially anticipated. Customers who placed orders between November 2019 and August 2021 are impacted...
Initially, the damage was thought to be limited, but it was revealed that past order data had not been deleted as expected, leading to an expansion of the affected customer base to over 80,000.
Past Data That Should Have Been Deleted Remains, Expanding the Scope of Damage
The issue became apparent in August when unauthorized access to ShipMonk's system resulted in the leak of Trezor customer personal information. Initially, Trezor reported that 13,689 customers were affected and explained that the damage was limited due to operations that delete or anonymize data within 90 days of shipping.
However, on September 2, additional information from ShipMonk revealed that order data from November 2019 to August 2021 had also been leaked. This resulted in approximately 67,000 new U.S. customers being affected, with names, email addresses, phone numbers, shipping addresses, and order numbers being compromised.
Trezor stated that it had repeatedly confirmed in writing that old order data was deleted based on its contract and data policy with ShipMonk. Nevertheless, the company expressed strong disappointment that data had actually remained.
The background to the significant expansion of the damage lies in the fact that past order data, which had been confirmed as deleted, was actually left in ShipMonk's system.
Wallets Are Safe, Caution Against Phishing and Impersonation
On the other hand, Trezor emphasized that the breach occurred on ShipMonk's system and that its own systems and Trezor devices were not affected.
However, the company warned that leaked names, addresses, and contact information could be used for phishing scams and social engineering. Attackers may impersonate Trezor, financial institutions, or cryptocurrency exchanges, reaching out via email, phone, or mail.
Trezor has already notified affected customers directly via email, urging them not to enter their wallet backup information on websites or share it with third parties. The company also cautioned about potential physical security risks arising from the leaked address information.
In response to this incident, Trezor plans to conduct additional audits of its shipping partners and implement anonymous shipping to reduce the sharing of customer information.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Decrypt Media and FOMO Hour’s Thought Leader Farokh Sarmad to Take Main Stage at NEXTPredict NY Conference

Bitcoin Developers Concerned About Mining Subsidy

The Three Words and One Answer from Yesterday's Press Conference: Wall Street is Pondering 'Waller's Approach'

Anthropic Introduces Context Lock for Claude to Prevent Model Distillation

The NFT party is over and everybody now owes storage rent

Costa Rica warns about crypto assets in political financing and strengthens its controls

Saylor: The era of intelligence and digital assets needs a bill of rights

Washington has $114 billion reasons to want Tether around

How Crypto Stopped Waiting for Congress and Learned to Love the Regulators

Balancer fork’s 6 million BAL ask could cut holders’ redemption value

FinCEN Expands AI Fraud Loophole in the USA by Eliminating Controls

Strategy Plans to Distribute Bitcoin Treasury Dividends Daily

Sharplink CEO: The Future of the Smart Economy

Fed stablecoin proposal would make circulation a capital cost for supervised issuers

Shielded Bitcoin: the proposal that aims to bring privacy without changing BTC's code

End of Bets in Brazil: What Changes and What Are the Next Steps

Galaxy Research: CFTC's 'Mention Markets' Guidance Highlights Structural Manipulation Risks in Individual Speech Predictions

What is CBDC? Governments Push for Development of Central Bank Digital Currencies

Why cash hoarding in the UK proves the world still craves permissionless money

OG.com Submits Application for US Stock Perpetual Contracts to CFTC Following Coinbase, Kalshi, and Kraken's Parent Company Payward

Crypto: $2.1 trillion evaporated, on-chain economy only loses 1.6%

Trump Rejects Iran Ceasefire, Expects Bombing After Midterms: Will Oil and Bitcoin Hold?

Solana’s Alpenglow upgrade reaches devnet with 150ms finality target

Bull Signal for Bitcoin: In 4 out of 5 Past Instances, Prices Increased

Statement on the Misreporting of the Fomo App by BlockBeats

Ripple’s RLUSD supply nears $2.5B as XRPL stablecoins climb 6%

唐华斑竹 Calls for Resumption of DOG Spot Trading

Google Trends: Bitcoin Gains Ground Against AI

唐华斑竹: Quantum Computing Becomes a Core Risk Point in the Cryptocurrency Field








