Trezor Breach Expands to 67,000 More Users Due to ShipMonk Failure
Trezor, a leading hardware wallet manufacturer, has disclosed that an additional 67,000 customers in the US were affected by a data breach at its shipping partner ShipMonk. This revelation expands the scope of the breach beyond the initial estimate of approximately 14,000 affected users announced on August 13.
The compromised information includes complete customer names, email addresses, phone numbers, physical mailing addresses, and purchase identifiers for customers who made purchases between November 2019 and August 2021. Trezor emphasized that its internal infrastructure remained untouched during this incident and no cryptocurrency funds stored within user wallets were directly compromised or accessed.
Trezor had repeatedly requested ShipMonk to purge legacy customer information from their databases, with written verification confirming the data elimination had been completed. However, it appears that the data was not deleted in their systems, leading to this expanded breach.