
Trezor Expands Breach Impact: 67,000 More US Customers at Risk
Vexoda Newsroom
Hardware wallet provider Trezor has revealed that a shipping partner's data breach now affects an additional 67,000 US customers, increasing the risk of phishing and social engineering attacks.
Hardware wallet manufacturer Trezor has announced an expansion of a previously disclosed data breach, indicating that an additional 67,000 United States-based customers are now impacted. This latest update stems from ongoing investigations with their shipping and fulfillment partner, ShipMonk. The exposed data includes sensitive personal information, potentially leaving these users vulnerable to malicious actors seeking to compromise their digital assets through deceptive tactics.
The compromised information for these 67,000 individuals encompasses full names, email addresses, phone numbers, physical shipping addresses, and details about their specific orders. Trezor stated that the exposure occurred for customers who placed orders between November 2019 and August 2021. This situation arises from allegations that ShipMonk failed to securely delete customer data, despite prior assurances from the shipping provider that such information would be handled appropriately and removed after fulfillment.
This latest disclosure significantly broadens the scope of the incident, which was initially estimated in August to affect around 14,000 users. Furthermore, Trezor had previously warned in January 2024 about potential risks to approximately 66,000 users who had contacted their support team since December 2021. It is crucial to note that Trezor's own internal systems were not breached; the vulnerability lies with the third-party logistics provider responsible for handling physical shipments and associated customer data.
The primary concern following this data leak is the increased risk of sophisticated phishing and social engineering attacks. Cybercriminals can leverage the exposed personal details to craft highly convincing impersonation schemes, potentially posing as Trezor support staff or representatives. The goal of such attacks is typically to trick users into divulging their private keys or seed phrases, which are essential for accessing and controlling cryptocurrency held in their hardware wallets.
This incident highlights a persistent and growing threat within the cryptocurrency ecosystem. Phishing and social engineering scams, as opposed to direct system exploits, have become a leading cause of crypto-related losses. According to security firm Hacken, these types of impersonation-based fraudulent activities accounted for a substantial portion of the total industry losses in the first quarter of the year, underscoring the effectiveness of these deceptive methods against even technically aware users.
Trezor users, particularly those within the affected group, are strongly advised to remain vigilant against any unsolicited communications. Traders should exercise extreme caution with any emails, messages, or calls that request personal information or prompt them to interact with their wallets or seed phrases. It is recommended to only use official Trezor channels for support and to never share sensitive recovery information, as Trezor itself does not ask for such details.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.