Trezor Data Breach Expands to 81,000 Customers Following ShipMonk Failure
AI-generated from multiple sources. Verify before acting on this reporting.
SAN FRANCISCO — The cryptocurrency hardware wallet maker Trezor announced on Monday that a data breach at its shipping logistics partner, ShipMonk, has exposed the personal information of an additional 67,000 U.S. customers, bringing the total number of affected individuals to 81,000.
The incident stems from a failure by ShipMonk to delete customer data from its systems in accordance with Trezor's contractual agreements and data retention policies. The exposed information was accessible through an unsecured vulnerability in Metabase, a third-party analytics platform utilized by the logistics provider. While the initial breach involved a smaller subset of records, the discovery that ShipMonk retained data beyond the agreed-upon deletion window significantly expanded the scope of the compromise.
The affected customer base includes residents of the United States, as well as individuals in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom. The compromised data reportedly includes names, shipping addresses, email addresses, and order details. Trezor stated that no cryptographic keys or wallet access credentials were stored on ShipMonk's servers, meaning the security of users' digital assets remains intact despite the exposure of personal identifying information.
Trezor has notified affected customers directly via email and updated its public incident response page with the new figures. The company emphasized that it had not authorized the retention of this specific data set, which was supposed to be purged after order fulfillment. ShipMonk acknowledged the security lapse, stating that the vulnerability in the Metabase instance allowed unauthorized access to the retained records.
The breach highlights ongoing challenges regarding data governance in third-party supply chains for cryptocurrency firms. Trezor has initiated a review of its vendor management protocols and is working with cybersecurity experts to ensure no further data remains exposed. The company is also offering credit monitoring services to affected users as part of its remediation efforts.
Regulatory bodies in several jurisdictions, including the U.S. Federal Trade Commission and European data protection authorities, have been notified of the incident. It remains unclear whether ShipMonk faces immediate legal repercussions or if Trezor will pursue further action regarding the contract violation. As of Monday afternoon, investigators are still determining the full timeline of when the vulnerability was first exploited and how long the data remained accessible before being secured.
The cryptocurrency community has reacted with concern over the expanding scope of the breach, raising questions about the security practices of logistics partners handling sensitive user data. Trezor continues to monitor the situation and has pledged to provide further updates as more information becomes available regarding the extent of the data exposure and potential follow-up actions by regulators.