mt logoMyToken
ETH Gas
EN

Trezor Says ShipMonk Data Breach Exposes 67,000 More US Customers

bitcoin-wallet2

Hardware wallet maker Trezor disclosed on September 4 that a data breach at its shipping provider ShipMonk is larger than first reported, affecting roughly 67,000 additional U.S. customers, according to the company’s security update .

A Wider Breach Than First Disclosed

Trezor said it learned on September 2 that the breach, first announced on August 10, also contained order data from its prior cooperation with ShipMonk between November 2019 and August 2021. The company added that it had repeatedly received written assurance from ShipMonk that the data had been deleted, only to find that the records remained in the provider’s systems.

The original disclosure had placed the number of affected customers at 11,742 with full exposure and 1,947 with partial exposure. The newly identified records push the total past 80,000 customers, most of them in the United States. Trezor attributed the gap to its 90-day data retention policy, under which fulfillment partners are supposed to delete or anonymize order data after delivery, a window the older records evidently slipped past.

What Was Exposed

The additional records include full exposure of names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor said it has emailed every newly identified customer directly from its security address and advised people who did not receive a notice that they are not affected. The company noted the parcel contents were not part of the breach.

Trezor called the incident the first time since its founding in 2013 that a breach exposed customer phone numbers and shipping addresses. ShipMonk stores products and ships orders for Trezor customers in the United States, the United Kingdom, and several other countries.

Phishing Risks and a Secure Device

Trezor stressed that its own systems were not compromised and that customer devices, private keys, and wallet backups remain secure. The main consequence, it said, is a higher risk of phishing, because the leaked information could be used for fraudulent emails, calls, and letters, including attempts to impersonate banks, exchanges, or Trezor itself. The company urged users never to enter a wallet backup on a website or share it with anyone.

The incident lands amid a broader push by wallet makers to market self-custody hardware such as the Trezor Safe 7 , and follows partnerships like the one with Bazaars to secure the Web3 economy .

Disclaimer: This article is copyrighted by the original author and does not represent MyToken’s views and positions. If you have any questions regarding content or copyright, please contact us.(www.mytokencap.com)contact
More exciting content is available on
X(https://x.com/MyTokencap)
or join the community to learn more:MyToken-English Telegram Group
https://t.me/mytokenGroup