Trezor Data Breach Exposes Personal Info of 67,000 Customers
A data breach has exposed the personal information of approximately 67,000 Trezor customers. The affected individuals placed orders between November 2019 and August 2021 via ShipMonk, a third-party provider used by Trezor for order fulfillment and shipping in the U.S.
The leaked records contain names, email addresses, phone numbers, shipping addresses, and order numbers, but do not include seed phrases or private keys. This distinction is crucial because it means that customers' cryptocurrency assets remain secure within their hardware wallets.
Trezor emphasized that its internal systems were not compromised, and the breach does not affect the security of its devices or cryptographic mechanisms. However, the exposure of personal information creates a significant risk of targeted scams, particularly phishing campaigns that can be convincing due to the availability of detailed customer data.
The incident highlights concerns about third-party data management, including ShipMonk's failure to delete customer records after they were no longer needed. This lapse allowed older order data to remain accessible and fall within the expanded scope of the breach.