← All news
CRYPTO NEWS

Trezor Data Breach Now Impacts Additional 67K US Customers

Cointelegraph · Zoltan Vardai

Hardware wallet provider Trezor has revealed that the scope of its recent data breach is larger than initially estimated, impacting an additional 67,000 US customers who ordered between November 2019 and August 2021. Exposed personal information includes full names, shipping addresses, emails, and order details. Trezor has pointed to its shipping partner ShipMonk for failing to delete customer data despite written assurances. The breach raises concerns over phishing attempts aiming to steal customers’ wallet seed phrases by impersonating Trezor.

Details of the Breach and Trezor’s Response

Trezor announced that the data breach now affects approximately 67,000 additional US customers following updated information from its shipping provider, ShipMonk. These customers ordered hardware wallets between November 2019 and August 2021, exposing full personal details including names, emails, phone numbers, shipping addresses, and order specifics.

Trezor emphasized that its internal systems were not compromised. The breach stemmed from ShipMonk’s failure to delete customer data as previously assured in writing, leading to unauthorized exposure of sensitive information.

History and Scale of the Incident

Back in August, Trezor initially estimated that around 14,000 customers were affected by the shipping provider's data exposure. Further, in January 2024, they reported approximately 66,000 individuals were at risk of phishing attacks, particularly those who had contacted Trezor support from December 2021 onwards.

The latest update expands the scope to include thousands more customers from earlier order periods, significantly increasing the number of users potentially vulnerable to fraudulent schemes.

Implications for Customer Crypto Asset Security

Although Trezor’s internal systems were not hacked, the data breach poses substantial risks to the security of users’ digital assets. Attackers may leverage the leaked personal information to conduct sophisticated phishing scams impersonating Trezor representatives, with the intent to trick victims into revealing their seed phrases—the cryptographic keys controlling their wallets.

Such social engineering attacks have driven the majority of crypto industry losses in Q1 2024, with phishing alone accounting for $306 million out of $482 million total lost, according to blockchain security firm Hacken.

Examples of Phishing Damage in Crypto

In July, a cryptocurrency investor lost nearly $1 million after unknowingly signing a malicious token approval on Ethereum, a classic phishing exploit. This incident underscores the severe financial consequences of social engineering attacks, especially amid expanding data breaches compromising user information.

Why it matters

This news highlights the tangible risk posed to hardware wallet users from personal data breaches that can fuel widespread phishing attacks and asset theft. Trezor, a leading provider, suffered not from a direct hack of their systems but due to a failure in their logistics partner’s data handling—emphasizing the critical need for end-to-end security throughout customer service chains. The increase of affected users by tens of thousands expands the potential scope of financial damage across the crypto sector and serves as a cautionary example of vulnerabilities linked to supply chains and social engineering scams.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗