Trezor Expands Data Breach Toll to 81,000 Customers After Shipping Partner Leak
Trezor, a leading maker of cryptocurrency hardware wallets, announced that a data breach at its third‑party logistics provider, ShipMonk, has now exposed personal information belonging to an additional 67,000 U.S. customers, bringing the total number of affected individuals to 81,000.
The breach, which originated in August, involved unauthorized access to a ShipMonk database that stored shipping details for Trezor orders. While the compromised data set is said to include names, email addresses, and shipping addresses, the company clarified that no wallet seed phrases, private keys, or financial transaction data were part of the leak.
Security experts note that even seemingly innocuous data such as mailing information can be leveraged in phishing campaigns targeting cryptocurrency users, who are often high‑value targets. "Attackers can craft highly credible messages when they already know a victim’s name and the product they recently purchased," said a cybersecurity analyst who follows hardware‑wallet security trends.
Trezor responded by notifying affected customers via email, urging them to remain vigilant for suspicious communications and to verify any requests for account details directly with the company. The firm also indicated that it is working with ShipMonk to tighten data‑handling procedures and has engaged an independent forensic team to assess the full scope of the incident.
The incident arrives amid growing scrutiny of supply‑chain security in the cryptocurrency ecosystem. Regulators in several jurisdictions have begun to focus on how crypto‑related firms protect customer data, and the breach could prompt further guidance or enforcement actions. Industry observers suggest that the episode underscores the need for hardware‑wallet manufacturers to audit not only their own systems but also those of every service provider handling sensitive customer information.
Looking ahead, Trezor has pledged to review its vendor‑management policies and to implement additional encryption measures for any data transferred to third parties. Customers who remain concerned can contact Trezor support for more information about the breach and any recommended protective steps. The company’s swift public disclosure aligns with best practices for incident response, but the expanding impact of the breach serves as a reminder that the security of crypto assets extends beyond the devices themselves.
Comments (0)
Be the first to comment.
Join the discussion