Trezor Discloses ShipMonk Breach Affecting 67K U.S. Customers
Hardware wallet maker Trezor revealed a third-party logistics breach exposing personal data of 67,000 U.S. customers. No financial or device security data was compromised.
TL;DR
- Trezor disclosed a breach at shipping partner ShipMonk affecting 67,000 U.S. customers
- Exposed data includes names, emails, phones, addresses, and order numbers from Nov 2019–Aug 2021
- Trezor stated previously deleted data was accessed, raising questions about data retention
- No impact on hardware wallet security or financial information reported
- Highlights ongoing risks of third-party vendor breaches in supply chains
Trezor, a well-known hardware wallet manufacturer, has disclosed a significant data breach involving its shipping provider ShipMonk. The incident exposed sensitive personal information of approximately 67,000 U.S. customers, marking another example of how third-party vendors can pose substantial security risks.
According to Trezor's disclosure, the breach occurred between November 2019 and August 2021, during which customer data including names, email addresses, phone numbers, shipping addresses, and order numbers were potentially compromised. While the company emphasized that no financial data or hardware wallet security was affected, the incident raises concerns about data retention practices and vendor risk management.
Breach Details and Timeline
- The breach occurred between November 2019 and August 2021 at ShipMonk fulfillment centers
- Approximately 67,000 U.S. Trezor customers had personal information exposed
- Data included names, email addresses, phone numbers, shipping addresses, and order numbers
- Trezor claimed the data had been previously deleted but was still accessible during the breach
- No cryptocurrency assets or hardware wallet functionality were compromised
Security Implications
- Highlights risks associated with third-party logistics and fulfillment partners
- Demonstrates importance of proper data retention and deletion verification processes
- Shows how supply chain partners can create extended attack surfaces for organizations
- Reinforces need for comprehensive vendor risk assessment and monitoring programs
- Serves as reminder that breaches can expose customer data even when core systems remain secure
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.