Trezor Announces Expansion of Data Breach Impacting Approximately 67,000 U.S. Customers
Trezor, a leading cryptocurrency hardware wallet provider, announced on September 4 that approximately 67,000 U.S. customers were affected by a data breach involving its shipping partner, ShipMonk.
Two days ago, we received an update from our shipping partner, ShipMonk. It is unfortunate to inform you that more customers have been affected by the recent data leak than initially anticipated. Customers who placed orders between November 2019 and August 2021 are impacted...
Initially, the damage was thought to be limited, but it was revealed that past order data had not been deleted as expected, leading to an expansion of the affected customer base to over 80,000.
Past Data That Should Have Been Deleted Remains, Expanding the Scope of Damage
The issue became apparent in August when unauthorized access to ShipMonk's system resulted in the leak of Trezor customer personal information. Initially, Trezor reported that 13,689 customers were affected and explained that the damage was limited due to operations that delete or anonymize data within 90 days of shipping.
However, on September 2, additional information from ShipMonk revealed that order data from November 2019 to August 2021 had also been leaked. This resulted in approximately 67,000 new U.S. customers being affected, with names, email addresses, phone numbers, shipping addresses, and order numbers being compromised.
Trezor stated that it had repeatedly confirmed in writing that old order data was deleted based on its contract and data policy with ShipMonk. Nevertheless, the company expressed strong disappointment that data had actually remained.
The background to the significant expansion of the damage lies in the fact that past order data, which had been confirmed as deleted, was actually left in ShipMonk's system.
Wallets Are Safe, Caution Against Phishing and Impersonation
On the other hand, Trezor emphasized that the breach occurred on ShipMonk's system and that its own systems and Trezor devices were not affected.
However, the company warned that leaked names, addresses, and contact information could be used for phishing scams and social engineering. Attackers may impersonate Trezor, financial institutions, or cryptocurrency exchanges, reaching out via email, phone, or mail.
Trezor has already notified affected customers directly via email, urging them not to enter their wallet backup information on websites or share it with third parties. The company also cautioned about potential physical security risks arising from the leaked address information.
In response to this incident, Trezor plans to conduct additional audits of its shipping partners and implement anonymous shipping to reduce the sharing of customer information.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

DEEPCOIN Completes System Penetration Testing with HackenProof to Strengthen Asset Security

Trezor and BitBox warn users of phishing emails exploiting STM32 vulnerability alert

Public Salaries Drop 40.5% Under Milei, Police and Military Most Affected

Phishing Emails Impersonating BPI Employees Distributed, Official Domain is 'btcpolicy.org'

XRP Healthcare Ceases Operations, XRPH and XRPHAI Tokens to be Delisted

Empowa DeFi Platform Reports Theft of 143,710 ADA and 4,240,000 EMP

Loans up to 1 billion UAH, state property rental, and business security

Marchenko Warns of Funding Shortages and Salary Delays

New Cryptocurrency Law in Poland, Strengthening Control of Authorities

Two Teachers from Ussuriysk Lost Over 2 Million Rubles in Fake Crypto Investments

Houthi Forces Take Control of Mocha Port, Increasing Risks for Red Sea Shipping

New Underground Money Laundering Scheme Using Virtual Currency, Seven Sentenced

PinGo Announces Contract Upgrade to Enhance Security

Anthropic Confirms Claude Model Cybersecurity Incident, Reveals Bias Reasoning and Recklessness Issues

Fake Security Email Targets Trezor Users

Strategy Signs MOU with Naver Cloud for AI Innovation

California Governor Signs AI Safety Bills to Regulate Third-Party Security Assessment Mechanisms

DSRV Integrates Canton Coin Custody Service

Bithumb Warns Against Fake AI Trading Malware

Bitcoin Mining Farm Dismantled in Puebla, Mexico

Solana Foundation Joins Rust Foundation as Platinum Member

Citrea Suspends Cross-Chain Transfers of ctUSD and Other Assets Due to Zentra Finance Security Incident

National Energy and Climate Plan Achieved 59% Completion

BitcoinHabebe Questions Trust Wallet Security, Emphasizes WEEX Safety Guarantee

Ledger Appoints Oded Blatman as Chief Information Officer and Chief Security Officer

Algorand Appoints William Herkelrath as New CEO

Solar Power Plant Launched at Chernobyl Nuclear Power Plant with Capacity of 2 MW

22-Year-Old Malone Lam Admits to $245 Million Crypto Heist

Safe to Launch 'Safe Pro' on October 6




