Trezor logistics provider ShipMonk data breach expands, affecting an additional 67,000 American users
Hardware wallet manufacturer Trezor updated the progress of the data breach incident involving its logistics partner ShipMonk, stating that the previously disclosed scale of the breach was underestimated. Additionally, information of approximately 67,000 U.S. users who placed orders between November 2019 and August 2021 was fully exposed, including names, email addresses, phone numbers, shipping addresses, and order numbers.
Trezor stated that it had previously confirmed multiple times with ShipMonk that the relevant data had been deleted according to the contract and data policy and had received written assurances, but the data was not actually deleted from the other party's system. Trezor claimed that its own system was not affected, and the hardware wallets remain secure, but affected users may face a higher risk of targeted phishing attacks. All affected users have been individually notified via email.
This incident was first disclosed on August 13, affecting approximately 13,700 users. Trezor stated that it is accelerating the launch of an anonymous shipping service to reduce the risk of information exposure when users place orders.






