Trezor has widened its customer breach notification after former shipping partner ShipMonk told the hardware wallet maker that older order records had remained in ShipMonk’s systems and were exposed in the same security incident first disclosed in August.
According to Trezor, the newly identified records affect about 67,000 customers in the United States. The company said the exposed information includes names, email addresses, phone numbers, shipping addresses, and order numbers, while stressing that its own systems and hardware wallets were not compromised.
Older records found in ShipMonk systems
Trezor said ShipMonk informed it on September 2 that order data from November 2019 through August 2021 had been retained inside ShipMonk’s infrastructure. Those records, Trezor said, were swept up in the same breach that ShipMonk had already reported in August.
The disclosure significantly expands the scope of the known exposure beyond the smaller set of recent-order data that Trezor first announced on August 13. The newly identified records relate specifically to U.S. customers.
What data was exposed
The company said the compromised records contain personally identifiable order information rather than wallet or device security data. Trezor listed the affected fields as full names, email addresses, phone numbers, shipping addresses, and order numbers.
Trezor said all customers included in this expanded breach have been contacted directly by email from help@trezor.io. It added that customers who did not receive such a notice are not regarded as part of this newly broadened incident.
Trezor criticizes ShipMonk over retention assurances
In its update, Trezor said it was disappointed that the older customer data had not been deleted despite what it described as repeated written assurances from ShipMonk over the course of their business relationship.
Trezor said those assurances were tied to contractual terms, its data policy, and ShipMonk’s 90-day retention policy. The company said it had repeatedly requested confirmation that customer data from the earlier partnership had been erased, but the records were still present in ShipMonk’s systems when the breach occurred.
Security risks and next steps
Trezor said the incident originated entirely within ShipMonk’s infrastructure. It stated that neither Trezor’s internal systems nor its hardware wallets were breached.
Even so, the company warned affected customers about increased phishing danger and possible physical security risks because the exposed records include contact and shipping details. For now, the confirmed next step is Trezor’s direct outreach to affected users, while the broader incident remains tied to the breach first reported in August.
Source: dailyhodl.com