$ techbeacon▋
Breaches

Trezor Reveals Additional 67,000 U.S. Customers Affected by ShipMonk Data Breach

Trezor Reveals Additional 67,000 U.S. Customers Affected by ShipMonk Data Breach

Trezor, the maker of popular cryptocurrency hardware wallets, announced on Friday that a second wave of personal data from its U.S. customers has been exposed in a breach of its logistics partner, ShipMonk. The company said the breach involved the personal details of roughly 67,000 individuals whose orders were processed through the third‑party shipping service.

The compromised information includes customers' full names, email addresses, telephone numbers, shipping addresses and details about the orders placed with Trezor. According to Trezor, the data was originally thought to have been deleted by ShipMonk after an earlier incident, but the latest investigation uncovered that copies remained accessible to unauthorized parties.

ShipMonk, which provides fulfillment services for a range of e‑commerce businesses, confirmed that it experienced a security incident earlier this year that allowed attackers to retrieve stored customer records. While the firm has not disclosed the exact method of intrusion, it acknowledged that the breach affected multiple clients and pledged to enhance its security protocols.

The revelation arrives amid heightened scrutiny of supply‑chain vulnerabilities, especially for companies handling sensitive financial tools like hardware wallets. Trezor, a subsidiary of SatoshiLabs, has built its reputation on protecting crypto assets through offline storage, yet the incident underscores that peripheral services can become weak points in an otherwise secure ecosystem.

In response, Trezor has urged affected users to monitor their email accounts for phishing attempts, verify any unexpected communications, and consider updating passwords associated with their Trezor accounts. The company also stated that it is working with cybersecurity experts and law enforcement to assess the scope of the breach and to prevent future exposures.

Regulatory bodies in the United States, including the Federal Trade Commission, have taken an interest in the case, as the compromised data falls under consumer privacy statutes. Depending on the outcome of investigations, ShipMonk could face penalties or be required to implement stricter data‑handling standards.

Industry analysts note that the incident highlights the importance of end‑to‑end encryption and rigorous vendor risk management for firms dealing with high‑value digital assets. As the crypto sector continues to mature, expectations for comprehensive security—beyond the core product—are likely to increase.

Customers who believe they may be impacted are advised to stay alert for official communications from Trezor, review the company's support resources, and remain vigilant against unsolicited requests for personal or financial information.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related