$ techbeacon▋
Breaches

Trezor Discloses Additional 67,000 U.S. Customers Affected in ShipMonk Data Breach

Trezor Discloses Additional 67,000 U.S. Customers Affected in ShipMonk Data Breach

Trezor announced on Thursday that a data breach involving its third‑party fulfillment partner, ShipMonk, has compromised the personal and order information of roughly 67,000 more U.S. customers, expanding the scope of an incident first reported in August.

ShipMonk, which handles warehousing and shipping for a range of technology firms, suffered unauthorized access to its systems earlier this year. At the time, Trezor disclosed that a limited number of its users were impacted. The latest investigation has revealed a much larger cohort of customers whose names, mailing addresses, email addresses and details of recent purchases were exposed.

The breach does not appear to include payment card numbers or encrypted wallet credentials, but the combination of contact information and order data could facilitate targeted phishing attacks or social‑engineering scams. Trezor urged affected users to remain vigilant, change passwords on any linked accounts, and monitor communications for suspicious activity.

In response, both Trezor and ShipMonk have launched forensic reviews and are working with cybersecurity firms to assess the full extent of the intrusion. ShipMonk has pledged to tighten its network segmentation and implement additional multi‑factor authentication controls, while Trezor said it is reviewing its data‑handling agreements with all third‑party service providers.

The incident underscores a growing trend of supply‑chain vulnerabilities, where attackers exploit trusted partners to reach high‑value targets. Crypto‑hardware manufacturers have faced similar challenges in recent months, prompting industry groups to call for standardized security audits of fulfillment and logistics vendors.

Regulators are likely to scrutinize the breach, especially given the sensitive nature of cryptocurrency‑related products. Trezor indicated that it will cooperate fully with any investigations and has already notified relevant U.S. authorities.

Customers who believe their information may have been compromised can request a copy of the data held about them through Trezor’s privacy portal. The company also plans to issue regular updates as the investigation progresses, emphasizing that protecting user data remains a top priority despite the setback.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related