Hardware wallet provider Trezor announced that an additional 67,000 US customers were impacted by a data breach at its shipping provider ShipMonk, significantly expanding the initially estimated scope of the incident.
The affected customers placed orders between November 2019 and August 2021, according to Trezor's Friday update citing ShipMonk. The exposed information includes names, email addresses, phone numbers, shipping addresses, and order details.
Trezor's systems were not directly compromised. However, the company stated that ShipMonk failed to delete customer data despite receiving written assurances from the shipping provider that it would do so.
Phishing and Social Engineering Risks
The exposed personal information creates vulnerability to phishing attacks and social engineering scams. Attackers could impersonate Trezor to target customers and attempt to steal their seed phrases, which control access to digital assets stored in hardware wallets.
Social engineering and phishing attacks accounted for $306 million of the $482 million in total crypto losses during the first quarter, according to blockchain security company Hacken.
Expanding Scope of the Breach
In August, Trezor initially estimated that 14,000 users had data exposed through the shipping provider. Additionally, Trezor reported in January 2024 that approximately 66,000 users faced phishing attack risks if they had contacted the company's support team since December 2021.


