- The newly identified records cover orders made between November 2019 and August 2021.
- Exposed data includes names, emails, phone numbers, shipping addresses, and order numbers.
- Trezor claims ShipMonk confirmed old records were deleted, but data remained.
On September 4, Trezor said that the ShipMonk data breach affected about 67,000 more US customers than first thought, making it bigger than originally reported.
The newly identified records cover orders made between November 2019 and August 2021. The data exposed includes full names, emails, phone numbers, shipping addresses, and order numbers.
Trezor says ShipMonk informed it about the larger breach on September 2. The hardware wallet company says it had repeatedly asked ShipMonk to delete that customer data and had gotten written confirmation that it was done. However, apparently, those records were still present in ShipMonk’s systems.
This is Much Larger Than the Original Disclosure
The original breach in August affected around 13,689 customers. Of those, 11,742 had their name, email, phone, and shipping address fully exposed, while 1,947 had less detailed information compromised.
Not only does the new information make this a much bigger incident, but it also calls into question how long third-party providers hold onto data.
Trezor had previously mentioned a 90-day retention policy, meaning older order info was supposed to be deleted or anonymized, but these newly found records go all the way back to 2019.
Fortunately, the company stated its own systems weren’t breached, and there is no sign that customers’ private keys, backups, or devices were accessed through the ShipMonk incident.
For crypto users, this is dangerous because a database containing a person’s name, home address, phone number, and proof of a hardware wallet purchase is still a potential goldmine for criminals.
The Biggest Danger is Phishing
Trezor has warned affected customers to be on guard for a range of scams, including fake emails pretending to be from Trezor, fraudulent phone calls, scam letters, people posing as banks or exchanges, and anything trying to trick them into giving up their recovery phrase.
The most dangerous scam would be a highly personalized message claiming that the user’s Trezor needs an urgent security fix, then directing them to enter their seed phrase on a fake website.
Users should never enter their wallet backup or seed phrase into a website, app, email form, or message. Additionally, they should avoid clicking links in random emails or texts and double-check every detail through official channels. The company said it has contacted affected customers directly.
Related: Hackers Access Over 13,000 Trezor Users’ Data by Breaching Third-Party Shipping Company
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.




Be the first to comment