Hardware wallet manufacturer Trezor has said that a data breach first announced last month is worse than originally reported.
The Prague, Czech Republic-based company said Friday that an additional 67,000 U.S. customers had their names, emails, phone numbers, shipping addresses and order numbers leaked. The leaked data came from orders made between November 2019 and August 2021, according to Trezor.
Trezor first announced in August that data from 11,742 customers from the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal had been exposed — with names, emails, phone numbers and shipping addresses leaked.
Another 1,947 customers just had their names, cities and emails exposed in the breach.
In Friday’s announcement, Trezor said that its third-party fulfillment partner, ShipMonk, had falsely reassured the company about deleting customer data.
“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” Trezor wrote.
“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”
Neither Trezor nor ShipMonk immediately responded to Bitcoin Magazine’s questions.
Trezor first announced in August that the data had been leaked because ShipMonk experienced “unauthorized access to their systems containing customer data.”
The company added that it had directly emailed all customers involved in the breach. Trezor’s parent company, SatoshiLabs, told Bitcoin Magazine last month that it was investigating the incident.
Trezor is one of the most popular Bitcoin hardware wallet solutions, and also has support for storing other cryptocurrencies.
Bitcoiners’ personal data has been targeted by cybercriminals in the past: back in 2020, an unauthorized party accessed popular hardware manufacturer Ledger’s e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers.
At the start of this year, customers reported receiving emails from Global-e, Ledger’s payment partner, that a data breach at its cloud systems leaked sensitive customer data.
Facts Only
* Trezor stated an additional 67,000 U.S. customers had their names, emails, phone numbers, shipping addresses, and order numbers leaked.
* The leaked data covers orders made between November 2019 and August 2021.
* Data exposure previously affected 11,742 customers from the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal, involving names, emails, phone numbers, and shipping addresses.
* Another 1,947 customers had only their names, cities, and emails exposed.
* Trezor reported that third-party fulfillment partner ShipMonk failed to delete customer data despite written assurances.
* The breach was caused by ShipMonk experiencing unauthorized access to systems containing customer data.
* Trezor emailed all customers involved in the breach directly.
* Trezor's parent company, SatoshiLabs, is investigating the incident.
Executive Summary
Full Take
Sentinel — Human
The text appears to be grounded in specific corporate announcements and contextual history, exhibiting characteristics consistent with human-authored reporting rather than purely synthetic generation.
