Trezor Expands Data Breach Notification to Over 81,000 Customers Following Shipping Provider’s Non-Compliance

Prague, Czech Republic – [Current Date] – Cryptocurrency hardware wallet manufacturer Trezor has significantly expanded its data breach notification, revealing that a breach initially affecting nearly 14,000 customers has now impacted an additional 67,000 U.S. individuals. The expanded scope stems from the continued exposure of customer data by its shipping and logistics provider, ShipMonk, which allegedly failed to adhere to contractual obligations regarding data deletion. In total, the incident now implicates approximately 81,000 Trezor customers.

The initial disclosure by Trezor on August 13, [Year], detailed that attackers had gained unauthorized access to sensitive information belonging to approximately 14,000 customers. This compromised data included full names, shipping addresses, email addresses, and phone numbers. At the time, Trezor clarified that the breach also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who had received orders between May 10 and August 8, [Year]. The company’s subsequent update on Friday confirmed that the full extent of the breach was not initially understood, primarily due to ShipMonk’s alleged non-compliance.

Trezor stated in its latest announcement that an additional 67,000 U.S. customers who placed orders between November 2019 and August 2021 had their full personal details – including name, email, phone number, shipping address, and order number – exposed. This expansion occurred because ShipMonk reportedly failed to delete the previously accessed data from its systems, a requirement stipulated in Trezor’s contract and data policy.

"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," Trezor communicated. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."

Chronology of the Data Exposure Incident

The unfolding data breach highlights a critical failure in third-party data handling, with significant implications for Trezor’s customer base. The timeline of events, as understood from Trezor’s disclosures, indicates a multi-stage exposure and a subsequent exacerbation due to non-compliance:

  • May 10, [Year] – August 8, [Year]: A period during which customers in various international locations (Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom) placed orders that would later be affected by the initial data exposure.
  • August 13, [Year]: Trezor publicly discloses a data breach affecting nearly 14,000 customers, detailing the types of personal information compromised and the affected international regions. The company attributes the breach to its shipping and logistics provider, ShipMonk.
  • [Date of Friday’s Update]: Trezor issues an update revealing a significant expansion of the breach’s scope. An additional 67,000 U.S. customers are now affected. This expansion is directly linked to ShipMonk’s alleged failure to delete previously exposed data, which was required by contract and Trezor’s data policy.
  • November 2019 – August 2021: The newly identified affected U.S. customers had placed their orders within this extended timeframe, indicating a longer period of potential data vulnerability with ShipMonk.

This extended timeline raises concerns about the diligence of data retention and deletion protocols within ShipMonk’s operations and the effectiveness of Trezor’s oversight of its third-party vendors.

The Role of Metabase and the ShinyHunters Gang

While Trezor has not explicitly detailed the initial method by which ShipMonk’s systems were breached, information gleaned from breach notification emails sent to affected customers points to a sophisticated cyberattack. These notifications reportedly indicate that attackers exploited a vulnerability within the third-party analytics platform, Metabase.

Metabase, a popular business intelligence tool, has itself been the subject of security advisories. As previously reported, threat actors have leveraged a critical SQL injection zero-day vulnerability in Metabase. This exploit allows attackers to gain administrator access to compromised instances, facilitating subsequent data theft. The implications of this vulnerability being exploited within ShipMonk’s infrastructure are profound, suggesting a broad potential for data exfiltration.

Furthermore, reports indicate that ShipMonk has received extortion demands from the notorious ShinyHunters extortion gang. This association suggests a potential motive for the data theft and raises the specter of further attempts at financial coercion against both ShipMonk and potentially its clients, including Trezor.

The Metabase campaign appears to be part of a wider pattern of attacks targeting companies that utilize the platform. Other notable entities impacted by similar breaches include the online form-building platform Tally and laptop manufacturer Framework. Both companies have also been compelled to notify their respective customer bases about data exposures resulting from hijacked Metabase instances.

Broader Context: Trezor’s Previous Security Incidents

Trezor data breach impact now reaches 81,000 customers

This latest incident adds to a history of security challenges for Trezor, underscoring the persistent threats faced by companies in the cryptocurrency sector. In January [Year], Trezor disclosed a separate data breach where threat actors compromised its third-party support ticketing portal. This earlier incident resulted in the unauthorized access of personal data, including names, usernames, and email addresses, belonging to approximately 66,000 users.

Crucially, the data stolen from that previous breach was subsequently weaponized in phishing attacks. These attacks specifically targeted recipients in an attempt to trick them into revealing their 24-word wallet recovery seeds – the master key to their cryptocurrency holdings. The reuse of stolen customer data for targeted phishing campaigns represents a significant escalation in the potential harm to individuals, as it directly jeopardizes the security of their digital assets.

The recurrence of data breaches, even those originating from third-party providers, places Trezor in a challenging position. It necessitates not only robust internal security measures but also rigorous vetting and continuous monitoring of all external partners who handle customer information. The cryptocurrency industry, by its very nature, is a prime target for cybercriminals due to the inherent value of digital assets, making robust security a paramount concern for both companies and their users.

Implications and Customer Guidance

The expanded data breach has significant implications for the affected 81,000 Trezor customers. The exposure of personal details like names, addresses, phone numbers, and email addresses significantly increases the risk of various cyber threats, most notably phishing attacks.

Trezor has issued a stern warning to its customers, urging them to remain vigilant against any unsolicited communications requesting personal information. The leaked data can be used to craft highly convincing scam emails, fraudulent phone calls, and even deceptive postal mail. These attacks are often designed to impersonate legitimate entities, including Trezor itself, or other trusted services, to extract sensitive credentials or financial information.

"Be aware of the increased risk of phishing," Trezor stated in its advisory. "The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks."

The mention of "physical security risks" is particularly concerning. When combined with shipping addresses, attackers could potentially use this information for malicious purposes such as doorstep scams, surveillance, or even more direct forms of harassment or physical intrusion. This underscores the interconnectedness of digital and physical security in the modern threat landscape.

For affected customers, immediate steps are recommended:

  • Scrutinize all communications: Exercise extreme caution with any emails, calls, or messages that request personal information, account details, or prompt immediate action.
  • Enable Two-Factor Authentication (2FA): Where possible, activate 2FA on all online accounts, especially those related to cryptocurrency exchanges, Trezor accounts, and email services.
  • Monitor financial accounts: Regularly check bank statements and credit reports for any suspicious activity.
  • Be wary of unsolicited offers: Scammers often use phishing to lure victims with fake investment opportunities or enticing offers.
  • Secure physical environment: While this is a digital breach, the exposure of addresses necessitates awareness of physical surroundings.

Trezor’s Response and Future Security Measures

In its communication, Trezor has emphasized that the breach did not compromise its own operational systems or services. The company asserts that its internal infrastructure remains secure, and all Trezor devices are unaffected and remain safe to use. This distinction is critical for maintaining customer trust, as it suggests the vulnerability lies with third-party handling of data rather than an inherent flaw in Trezor’s core product or platform.

However, the incident undoubtedly puts a spotlight on Trezor’s vendor risk management practices. The repeated assurances from ShipMonk regarding data deletion, followed by their apparent failure to comply, raises questions about the depth of Trezor’s due diligence and auditing processes for its partners.

Moving forward, Trezor is likely to reassess its contractual agreements with third-party logistics providers and enhance its auditing procedures to ensure strict adherence to data privacy and deletion policies. The company’s commitment to customer security will be tested by its ability to implement more robust oversight mechanisms and potentially diversify its logistics partners to mitigate reliance on a single point of failure.

The cryptocurrency hardware wallet market is highly competitive, with security being a primary selling point. Incidents like these, even when stemming from third parties, can erode customer confidence. Trezor’s proactive and transparent communication about the expanded breach is a positive step, but the long-term impact will depend on its ability to prevent similar occurrences and reassure its user base about the safety of their data and digital assets. The ongoing investigation into the precise method of ShipMonk’s breach and the extent of ShinyHunters’ involvement will be crucial in understanding the full scope of this security failure and informing future preventative measures across the industry.

Related Posts

CenterPoint Energy Confirms Customer Data Stolen in Cyberattack

CenterPoint Energy has confirmed a significant data breach, acknowledging that a portion of its customers’ personal information was accessed by an unauthorized third party. The disclosure follows a public announcement…

VMware vCenter Vulnerability Now Actively Exploited by Ransomware Gangs, CISA Warns

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a grave alert, confirming that sophisticated ransomware operations are now actively exploiting a critical vulnerability within VMware’s vCenter Server, a…

Leave a Reply

Your email address will not be published. Required fields are marked *

You Missed

TikTok User Mila Detained by ICE During Green Card Interview in San Diego, Sparking Widespread Debate Over Immigration Enforcement Practices

TikTok User Mila Detained by ICE During Green Card Interview in San Diego, Sparking Widespread Debate Over Immigration Enforcement Practices

The Expanse Osiris Reborn Hands-On Preview: Owlcat Games Translates Hard Sci-Fi RPG Pedigree into Third-Person Action

  • By admin
  • September 15, 2026
  • 3 views
The Expanse Osiris Reborn Hands-On Preview: Owlcat Games Translates Hard Sci-Fi RPG Pedigree into Third-Person Action

The AI race has grown so frenzied that, by 2035, U.S. data centers are projected to consume more natural gas than Germany and Japan combined.

The AI race has grown so frenzied that, by 2035, U.S. data centers are projected to consume more natural gas than Germany and Japan combined.

Thatch Secures $108 Million in Funding at $1 Billion Valuation, Reshaping Health Benefits for Startups

Thatch Secures $108 Million in Funding at $1 Billion Valuation, Reshaping Health Benefits for Startups

CenterPoint Energy Confirms Customer Data Stolen in Cyberattack

CenterPoint Energy Confirms Customer Data Stolen in Cyberattack

Google’s Latest Pixel Drop Will Keep You More Connected To Your VIPs

Google’s Latest Pixel Drop Will Keep You More Connected To Your VIPs