Trezor, the company known for its cryptocurrency hardware wallets, has revealed that a data breach involving its shipping provider ShipMonk affected far more customers than first reported. The total number of affected customers has now reached about 81,000, after another 67,000 customers in the United States were identified. Trezor had first disclosed the incident on August 13, when it said that nearly 14,000 customers had been affected. The newly identified customers placed their orders between November 2019 and August 2021.

The exposed information included important personal details belonging to the affected customers. For the newly identified U.S. customers, the information included their names, email addresses, phone numbers, shipping addresses and order numbers. The original group of affected customers also included people from the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor said that 11,742 customers from the original group had their full details exposed, while another 1,947 customers had partial information exposed.

The breach happened through ShipMonk, a company responsible for shipping and fulfilment services for Trezor. According to Trezor, it had repeatedly received written confirmation from ShipMonk that the customer information had been deleted as required under their agreement and data policy. However, Trezor later discovered that the information had not actually been deleted from ShipMonk’s systems. The company said it was very disappointed after learning that the data had remained available despite those previous confirmations.

Trezor has also made it clear that its own systems and hardware wallets were not compromised in the incident. However, the leaked personal information can still create security risks for customers because criminals may use the details to make convincing phishing messages, phone calls or impersonation attempts. Since some exposed information includes shipping addresses, Trezor is also warning customers about possible physical security concerns. The company has contacted customers affected by the latest disclosure and asked them to remain careful about suspicious communications.

The company is warning customers to be especially careful if they receive unexpected emails, phone calls or letters claiming to come from Trezor. Customers should never provide their wallet backup or seed phrase to anyone and should never enter it into a website because of a message or phone call. The leaked information could allow scammers to make their communication appear genuine by using a customer’s name, address or other known details. Trezor has therefore advised affected users to stay alert and treat unexpected requests involving their wallets with caution.

The latest disclosure significantly increases the size of the Trezor breach and shows why customer information handled by third-party service providers needs strong protection. What initially appeared to affect around 14,000 customers has now grown to approximately 81,000 customers after the additional U.S. records were identified. Trezor says it is working on measures such as anonymous delivery to provide better protection for customer information in future orders. For affected users, the main concern is not a direct compromise of their Trezor devices, but the possibility that leaked personal details could be used in targeted scams or other security attacks.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news