Trezor Data Breach Widens with 67k More Customers Exposed
Trezor has disclosed that an additional 67,000 US customers had their personal data exposed in a breach at its shipping provider, ShipMonk. This expands the total impact beyond the roughly 14,000 customers initially reported when Trezor first disclosed the breach on August 13.
The newly confirmed records cover orders placed between November 2019 and August 2021, including customer names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor had written assurances from ShipMonk that the data had been deleted, but it appears this was not done.
Affected customers face risks beyond online scams, including phishing attacks, scam calls, physical letters, and potential theft of crypto holdings. Trezor's own systems were not breached, and its hardware wallets remain secure, with no wallet funds directly accessed.