LATEST NEWS
SELECTED FOR YOU

Trezor says ShipMonk kept data it promised to delete

ByAshish KumarAshish Kumar 3 mins read
Trezor data breach expands to 80,700 users after ShipMonk leak
  • Trezor says the ShipMonk breach exposed data from another 67,000 U.S. users, bringing the total potentially affected to 80,700.
  • Exposed information includes names, addresses, phone numbers, emails and order details, but not private keys or wallet backups.
  • The leaked data could enable targeted phishing and social-engineering attacks against verified crypto-wallet users.

In an update issued on Friday, Trezor revealed that the data leak from its shipping partner, ShipMonk, was worse than previously believed. Specifically, the personal information, which includes names, addresses, phone numbers, email addresses, and order data, of another 67,000 users in the U.S. had been exposed.

Now, the total number of users whose data may have been compromised is 80,700. This makes holders with Trezor wallets at risk.

The new batch of data involves orders placed by U.S. customers between November 2019 and August 2021, as Trezor wrote in the post on X made on Friday.

Notably, some of that information is nearly seven years old. That is relevant because back in August, when Trezor announced the data leak, the 90-day data deletion policy implemented by its fulfillment partner was credited with limiting the number of impacted users.

Trezor data exposure surges to 80,700 users

The company explained that it had asked ShipMonk multiple times to provide documentation showing that the order data older than 90 days was deleted. Every time, the company received positive answers to those requests.

Now, Trezor expressed disappointment about the fact that those documents turned out to be incorrect. According to reports, Trezor placed the blame squarely on the shipping provider for keeping data it had promised to delete.

The new figures eclipse the old by a great deal. Back in August, Trezor estimated exposure to the breach to 14,000 people. However, ShipMonk reported findings to Trezor two days prior to its disclosure on Friday. That brings the tally up to around 80,700 users.

Trezor clarified that its systems have not been compromised; no devices, private keys or wallet backups were exposed, as the breach was conducted purely from the logistics end. Information, such as customer contact details and shipping, was compromised.

How a mailing list turns into a weapon

The danger here lies in targeting. The leak of a mailing list with verified owners of hardware wallets, including the addresses where crypto users reside, lets hackers target those exact people for phishing attempts via email, phone calls and even snail mail.

Trezor advised the affected users to be wary of such attempts and also highlighted the threat to personal safety.

The threat is very real. In February, owners of Trezor and Ledger wallets received forged letters printed with holograms, QR codes, and even fake signatures of executives urging them to perform a fake security test or be locked out of their accounts.

As noted by cybersecurity expert David Sehyeon Baek, a forged letter delivered with a real name and address changes the psychology of the scam.

The magnitude of the phishing problem

An impersonation scam does not necessarily require an exploit to steal from a user’s wallet. In fact, it is such scams that are already dominating cryptocurrency loss figures.

Blockchain cybersecurity firm Hacken found that phishing and social engineering scams made up $306 million of the $482 million total amount stolen within the first quarter of the year. One investor nearly lost $1 million by confirming a malicious token transaction on Ethereum in July.

Moreover, this is not the first time Trezor has faced a breach involving exposed user contact details. In January 2024, the company revealed that around 66,000 customers who have contacted its support team since December 2021 were exposed to phishing scams.

If you're reading this, you’re already ahead. Stay there with our newsletter.

FAQs

How many Trezor customers were affected by the ShipMonk breach?

Trezor now says roughly 80,700 customers are affected in total, after disclosing an additional 67,000 US users on Friday on top of the 13,689 it reported in August.

What information was exposed in the Trezor data breach?

The leaked records include customers' names, email addresses, phone numbers, home addresses and order numbers for US orders placed between November 2019 and August 2021, though Trezor's own systems, devices and private keys were not compromised.

Why is the exposed data dangerous if no wallets were hacked?

The records identify confirmed hardware wallet owners at specific home addresses, giving attackers a target list for phishing emails, calls, forged letters and physical-security threats aimed at stealing users' seed phrases.

Share this article

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Ashish Kumar

Ashish Kumar

Ashish Kumar is a crypto and financial journalist with eight years of newsroom experience. He covers what’s happening with crypto markets, regulation, DeFi, and exchange ecosystems. He has worked with Coingape, Todayq, and Newsroompost. Ashish holds a PGDP in English Journalism from the IIMC. He has also interviewed industry figures including Arthur Hayes, Yat Siu, Austin Federa, and more.

MORE … NEWS