Trezor breach exposes another 67,000 customers

Bybit
Blockonomics


Hardware wallet maker Trezor says a breach at logistics provider ShipMonk exposed contact and order data for another approximately 67,000 U.S. customers after years-old records remained in the vendor’s systems despite written deletion assurances.

The Sept. 4 update expands an incident Trezor initially said affected 13,689 people. The two disclosed groups imply a total of roughly 80,689, although Trezor has not issued a single combined figure or published underlying data showing whether the groups overlap. Its use of “another” indicates that it considers the new records additional to the original cohort.

Infographic showing Trezor's Aug. 13 disclosure of 13,689 affected customers, another approximately 67,000 disclosed on Sept. 4, the retained 2019 to 2021 order period, exposed contact and shipping fields, and systems and wallet secrets not compromised.Infographic showing Trezor's Aug. 13 disclosure of 13,689 affected customers, another approximately 67,000 disclosed on Sept. 4, the retained 2019 to 2021 order period, exposed contact and shipping fields, and systems and wallet secrets not compromised.

The newly disclosed records cover U.S. orders from November 2019 through August 2021 and include names, email addresses, phone numbers, shipping addresses and order numbers. The data can connect an identifiable person and physical location with a hardware-wallet purchase, creating risks beyond a conventional email leak.

Binance

Related Reading

With violent crypto home invasions surging, a data breach exposing over 10,000 Trezor owners puts physical safety on the line

Old data outlived a 90-day policy

When Trezor first disclosed the breach on Aug. 13, it counted 11,742 customers with full exposure and 1,947 with partial exposure. Trezor’s Aug. 13 account said older order data had already been deleted. An Aug. 14 clarification acknowledged that some partially exposed records included older orders.

The Sept. 4 update reverses that understanding. Trezor said it repeatedly requested and received written assurances that ShipMonk had deleted the data, yet records from 2019 to 2021 remained. Trezor’s published delivery-data policy says customer details should be deleted from both its own and its fulfillment partner’s systems after 90 days, with exceptions for ongoing order issues. The assurance letters and their dates have not been made public.