3 hours ago

ShipMonk breach exposes 67,000 more Trezor customers

67,000 More Trezor Customers Exposed as Data Breach Widens

Decrypt

A breach at shipping provider ShipMonk exposed 67,000 more Trezor customers. The total number of exposed records rose from 13,689 to roughly 80,700. The records included names, email addresses, phone numbers, home addresses and order numbers. All affected customers are in the U.S. The customers placed orders between November 2019 and August 2021. Some exposed records are close to seven years old. Trezor said ShipMonk passed on the finding two days ago. Trezor said it repeatedly received written confirmation that the records had been deleted under its contract and data policy. Trezor said it was disappointed to learn the records had not been deleted. Trezor's own systems were not breached. The breach did not affect devices, private keys or wallet backups. The exposed records identify confirmed hardware wallet owners at specific home addresses. Trezor warned affected customers about physical security risks from fake emails, calls and letters. Trezor also repeated that customers should never share a wallet backup or type it into a website. Owners of Trezor and rival hardware wallet Ledger had already received forged letters in February. The letters included holograms, QR codes and forged executive signatures. The letters demanded a fictitious security check to prevent loss of wallet access. Cybercrime consultant David Sehyeon Baek said a letter with a name and home address signals that the sender can locate the recipient. Baek said stolen data remains useful for years because people rarely move or change their phone numbers. The intrusion traces to a critical SQL injection flaw in the analytics tool Metabase. The flaw was disclosed on August 6. The flaw allowed unauthenticated attackers to steal credentials for connected databases. Laptop maker Framework and form builder Tally were caught in the same wave. ShipMonk has reportedly received extortion emails attributed to ShinyHunters. That attribution remains unconfirmed. Trezor said it is working to ship anonymous delivery as quickly as possible. The option uses locker pickup, neutral packaging and generic sender details so buyers do not need to provide a home address.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.