• security
  • news
  • 1 hour

Trezor Reports Data Leak Affecting Another 67,000 US Customers

The logistics company ShipMonk retained an archive of US orders from 2019–2021, even though it had confirmed in writing that the records had been destroyed.

0

nft.eu
  • rating +26
  • subscribers 113

On September 4, hardware wallet maker Trezor said that a data leak at its logistics partner ShipMonk affected another roughly 67,000 customers in the United States. The records cover orders placed between November 2019 and August 2021 and contain customers’ names, email addresses, phone numbers, shipping addresses, and order numbers.

The company emphasized that Trezor’s own systems and the hardware wallets themselves were not compromised. Orders placed through the official Amazon stores are fulfilled by a different partner and were not affected by the incident. The leak concerns orders placed through the trezor.io storefront and shipped by ShipMonk.

All customers whose data was exposed have already been notified about the incident.

On August 13, Trezor reported a data leak but described a smaller scope at the time: the company said 11,742 customers had their full details exposed, while another 1,947 customers had partial data exposed — their name, city, and email address. That disclosure affected customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who had received an order in the 90 days before August 8, 2026.

On September 2, ShipMonk provided Trezor with an update confirming that the compromised dataset also contained data from an earlier period of their partnership.

Trezor said that throughout its contract with ShipMonk, it required the logistics company to delete customer data and received written confirmations that the records had been erased in accordance with the contract and data-retention policy. For orders from 2019–2021, this was not related to the current 90-day retention rule, which did not yet exist under the first contract. Instead, Trezor had separately asked ShipMonk to destroy the entire archive after that stage of their partnership ended.

ShipMonk sent written confirmations stating that the data had been destroyed in accordance with the contract and its retention policy. That turned out to be untrue — the records remained in the logistics company’s systems.

Trezor said it is redesigning its fulfillment process and preparing an anonymous shipping option. With a future order, customers will be able to avoid providing the same amount of personal information.

Read also:

This post is for informational purposes only and does not constitute advertising or investment advice. Please do your own research before making any decisions.

0

Comments

0