- The Trezor data breach now affects more than 67,000 users in the US, as the information stolen from its shipping provider dates back as far as 2019.
Trezor, the world’s first hardware wallet, previously disclosed an unfortunate data leak affecting approximately 13,689 users across seven countries. ShipMonk, the product’s third-party shipping provider, took responsibility for the breach.
A new development in the investigation revealed that the number of affected users is significantly more than what Trezor estimated.
The Trezor Data Breach Is More Serious Than We Thought
Trezor announced on Friday that the data leak now covers roughly 67,000 customers in the US alone. Citing ShipMonk’s update, the hardware wallet provider explained that the dramatic increase in its affected users was due to the problem tracing back to orders between November 2019 and August 2021.
The company assumed that only deliveries completed within the past 90 days leading up to August 8 were exposed. It attributed this to its strict 90-day data storage policy.
Trezor claimed that the longer coverage of the data breach was mainly due to ShipMonk’s failure to adhere to its contract, data policy, and past communications. The latter allegedly repeatedly ensured the former that it never stored customer information longer than its 90-day data storage policy.
The wallet provider expressed “disappointment” over the matter. However, the business has yet to discuss any planned course of action against its shipping provider.
ShipMonk’s non-compliance with its agreement with Trezor exposes the affected users’ full details, including name, email, phone number, shipping address, and order number, to the attacker. It’s also worth noting that the new figures only accounted for customers in the US. It’s unclear whether there was an uptick in the number of other compromised wallet owners in the UK, Sweden, Colombia, Brazil, Italy, and Portugal.
Trezor assured users that its systems weren’t compromised. Nonetheless, with their sensitive information leaked to the hacker’s network, they have become exposed to targeted phishing attempts.
Reminders for Users
The company said it had already informed users about the more disappointing news. Additionally, it advised them to be more vigilant about fake emails, phone calls, and fraudulent letters. Worse, it warned them of potential physical security risks amid the rising number of wrench attacks on crypto holders.
Trezor strongly reminded users to never share their wallet backup, even with people claiming to be from its ranks. It likewise discouraged them from typing it into a website, even one that identifies with the company.
“We’re terribly sorry to everyone affected,” Trezor concluded its public announcement via social media. “We take this matter very seriously and are working to ship anonymous delivery ASAP, so you can protect your personal information when placing an order.”
What’s your Reaction?
+1
4
+1
2
+1
0
+1
0
+1
0
+1
0
+1
0
