67,000 More Trezor Customers Exposed as Data Breach Widens

Bybit
fiverr


In brief

  • Trezor said Friday that another 67,000 U.S. customers were caught in the ShipMonk breach it disclosed last month.
  • The records cover orders placed between November 2019 and August 2021, and include names, phone numbers and home addresses.
  • Trezor says it repeatedly received written confirmation from ShipMonk that the data had been deleted.

Another 67,000 Trezor customers had their names, email addresses, phone numbers, home addresses and order numbers exposed in the breach at shipping provider ShipMonk, the hardware wallet maker said on Friday.

All of them are in the U.S., and all placed orders between November 2019 and August 2021, making some of the exposed records close to seven years old. ShipMonk passed on the finding two days ago.

Trezor repeatedly asked for and received written confirmation that those records had been deleted, in line with its contract and data policy, and said it was disappointed to learn they had not been.

When it disclosed the breach in August, the company attributed its limited scope to a 90-day deletion policy it said it had negotiated into its fulfillment partners’ terms. That claim now looks considerably weaker. The count has gone from 13,689 to roughly 80,700.

bybit

Wallet owners face multiple threats

Trezor’s own systems were not breached, and devices, private keys and wallet backups are untouched. The danger is that the records identify confirmed hardware wallet owners at specific front doors. Alongside fake emails, calls and letters, Trezor warned affected customers about risks to their physical security, and repeated that a wallet backup should never be shared or typed into a website.

Owners of both Trezor and rival hardware wallet Ledger were already receiving forged letters in February, printed with holograms, QR codes and forged executive signatures, demanding they activate a fictitious security check or lose access to their wallets.

At the time, cybercrime consultant David Sehyeon Baek told Decrypt that a letter carrying a name and home address signals “we can locate you,” and that stolen data stays useful for years because people rarely move or change their numbers.

Myriad: Where does Ethereum price go next? Click to make your prediction.
Myriad: Where does Ethereum price go next? Click to make your prediction.

The intrusion traces to a critical SQL injection flaw in the analytics tool Metabase, disclosed on August 6, which let unauthenticated attackers steal credentials for connected databases. Laptop maker Framework and form builder Tally were caught in the same wave. ShipMonk has reportedly received extortion emails attributed to ShinyHunters, though that attribution remains unconfirmed.

Trezor said it is working to ship anonymous delivery as quickly as possible, an option using locker pickup, neutral packaging and generic sender details so that buyers need not hand over a home address at all.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Bitbuy

Be the first to comment

Leave a Reply

Your email address will not be published.


*