Trezor says a data breach at its shipping partner ShipMonk is far larger than first disclosed, with another 67,000 US customers now confirmed exposed. The total known number of affected customers has climbed past 80,000, and some of the newly found records are almost seven years old.
Trezor said in a new update from September 4 that another 67,000 customers in the United States had their personal information exposed in the breach at its shipping provider, ShipMonk, the hardware wallet maker's third-party logistics partner. These clients placed orders between November 2019 and August 2021, meaning some of the compromised records were almost seven years old.
CryptoPotato reported last month that Trezor had initially said the ShipMonk breach affected approximately 13,689 customers. Of that group, 12,742 had their names, emails, phone numbers, and shipping addresses exposed, while another 1,947 had more limited information compromised.
The latest discovery, though, shed more worrisome light on the incident, as much older customer information remained in ShipMonk's systems. Trezor said it had repeatedly requested, and received, written assurances from the logistics provider confirming the data had been deleted in accordance with its contract and data policy. According to Trezor: "the data was not deleted in their systems", the company said in an update on X.
Adding the newly identified customers brings the known number of affected users to more than 80,000. Trezor said all newly affected customers have been contacted directly by email, and that users who have not received a notification are not believed to be impacted.
Trezor's team emphasized that its own systems were not compromised and that its wallets remain secure. Private keys and wallet backups were not exposed in the ShipMonk incident.
Source: CryptoPotato
Trading involves risk.