Trezor data breach expands to over 80,000 customers after ShipMonk kept old records
The Trezor data breach has expanded after ShipMonk discovered that older customer records remained stored despite previous deletion assurances.
Trezor says another 67,000 US customers had their personal information exposed through a breach at its shipping provider, ShipMonk.
Since the problem was first reported earlier in August, more than 80,000 customers have been impacted. And there continue to be question marks over why ShipMonk still kept years-old order records even though they told Trezor that they had been securely deleted
Older Trezor orders were still on ShipMonk’s systems
The newly identified customers placed orders between November 2019 and August 2021. Exposed information includes names, email addresses, phone numbers, shipping addresses, and order numbers.
Trezor said it received more findings from ShipMonk two days before publishing its latest update and that everyone identified in the new group has been contacted directly by email.
This new disclosure comes after an earlier announcement that involved 13,689 customers. Out of those numbers, 11,742 had their names, contact details, and shipping addresses exposed, and the remaining 1,947 had fewer compromised details.
With the latest group announced, it brings the total number that is known, for now, to about 80,689 customers, and some of the records that were just exposed were almost seven years old!
Trezor said it had repeatedly asked ShipMonk to erase the information and received written assurances that it had done so, making the whole situation more disappointing after it was discovered that that was not the case.
Wallets remain secure, but customers face other risks
Trezor said that their own systems were unaffected by the breach, and customer wallet backups were not exposed, and the attacker did not have direct access to their crypto.
But the problem is, the stolen personal information could still be used to create convincing scams. Knowing a customer’s name, their orders, and how to contact them can be sufficient ammunition to assume Trezor’s identity in emails, and calls, or even letters.
More concerning are the shipping addresses that have been exposed, because they can be used to identify homes where hardware wallets are kept.
Trezor advised customers never to reveal their wallet backup or enter it on a website, regardless of who requests it. Also, that anyone who did not receive a notification email is not believed to be affected.
The company says it is now working to introduce anonymous delivery, which would allow buyers to order devices without sharing as much personal information.
Final Summary
- Another 67,000 US customers were added to the Trezor data that was breached.
- While the devices are said to remain secure, the leaked data could be used for targeted scamming attempts or pose a physical security risk.