Trezor Reports Shipping Provider Data Breach Exposes 67,000 More US Customers

The newly identified records were in addition to an earlier group of 13,689 affected customers: 11,742 had full information exposed, while 1,947 had more limited exposure involving their name, city and email address. The earlier records covered customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.
Trezor said it had emailed all customers in the newly identified group, adding that customers who did not receive a notification were not part of that additional 67,000-person cohort.
As a preventative measure for future orders, Trezor said it was working to offer anonymous delivery to reduce the amount of customer information exposed through shipping and fulfillment processes.
The breach emerged amid broader targeting of hardware-wallet owners: owners of Trezor and Ledger reportedly received forged letters featuring holograms, QR codes and fake executive signatures that demanded a bogus security check. Cybercrime consultant David Sehyeon Baek said a letter containing a recipient’s name and home address can signal, “we can locate you.”
CoinTelegraph cited Hacken data showing that impersonation-based phishing and social-engineering attacks accounted for $306 million of the crypto industry’s $482 million in losses during the first quarter of the year, underscoring the potential financial impact of the exposed customer information.
Trezor, a major cryptocurrency hardware wallet maker, disclosed that a data breach at its shipping partner ShipMonk exposed an additional 67,000 U.S. customers, bringing the total affected to roughly 80,700 people Protos. The newly revealed records included names, email addresses, phone numbers, shipping addresses and order numbers from customers who placed orders between November 2019 and August 2021. Trezor said its own systems and private wallet keys were not compromised, but the exposed personal data creates serious risks for targeted phishing scams and physical threats Bloomberg.
Trezor said it had repeatedly asked ShipMonk in writing to delete records from orders placed before August 2021 CoinTelegraph. The company expressed disappointment that the older customer data remained in ShipMonk's systems despite written assurances about data retention agreements. This discovery added 67,000 people to the earlier group of 13,689 affected customers that Trezor had identified from the ShipMonk breach.
The first wave of breached records affected 11,742 customers with full information exposed and 1,947 with limited data including name, city and email The Street. Those earlier victims came from seven countries: the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. The newly identified 67,000 were all U.S.-based customers. Trezor has emailed all affected people in the expanded group to notify them.
Trezor and Ledger customers have faced a separate coordinated attack involving fake letters with holograms, QR codes and forged executive signatures Crypto Politain. The letters demand a bogus security check and use personal information like names and home addresses to appear legitimate. David Sehyeon Baek, a cybercrime consultant, said having a recipient's name and address signals attackers "we can locate you." This broader targeting makes the ShipMonk leak especially dangerous for hardware wallet owners.
Impersonation-based phishing and social-engineering attacks accounted for $306 million of the crypto industry's $482 million in losses during the first quarter, according to Hacken data cited by CoinTelegraph CoinTelegraph. That means roughly 64% of all crypto theft came from tricks targeting people directly. The exposed customer data — names, addresses and email addresses — provides scammers with everything they need to launch convincing attacks. Trezor is now working to offer anonymous delivery options to reduce the information exposed through shipping.
Publishers
21
Articles
21
Reach
42