Additional 67,000 US Trezor Customers Impacted by Shipping Data Breach

Additional 67,000 US Trezor Customers Impacted by Shipping Data Breach

Hardware wallet manufacturer Trezor has disclosed that 67,000 additional American customers were compromised in a data breach at its shipping partner, creating new risks for phishing scams and social engineering attacks.

Hardware wallet manufacturer Trezor has revealed that the scope of its recent data breach extends far beyond original estimates, now encompassing an additional 67,000 customers based in the United States.

According to a Friday statement posted on X, the breach potentially puts at risk more American customers who placed orders during the period spanning November 2019 through August 2021, based on new information provided by the company's logistics partner, ShipMonk.

The exposed customer information was comprehensive, containing complete names, email addresses, phone numbers, physical shipping addresses, and details about their purchases. Trezor has pointed responsibility toward the logistics company for retaining this information, contradicting previous written guarantees from ShipMonk that the data had been purged.

Although Trezor's own infrastructure remained secure and uncompromised, the exposure of customer information at the shipping partner poses serious risks to the cryptocurrency assets belonging to these 67,000 affected individuals, as malicious actors could leverage this data to launch convincing phishing campaigns disguised as legitimate Trezor communications, attempting to trick users into revealing their seed phrases that provide access to their cryptocurrency wallets.

Earlier in August, Trezor's preliminary assessment indicated that approximately 14,000 users had been affected by the shipping provider's security incident. Previously, in January 2024, Trezor had disclosed that roughly 66,000 customers faced potential phishing threats if they had reached out to the company's customer support services any time after December 2021.

Unlike attacks that exploit technical vulnerabilities in software code, phishing campaigns and social engineering rely on human manipulation. Nevertheless, these impersonation-driven fraud schemes were responsible for the lion's share of financial losses in the cryptocurrency sector during the year's first quarter, representing $306 million out of a combined total of $482 million in stolen funds, based on data from blockchain security firm Hacken.

As recently as July, a cryptocurrency holder suffered losses approaching $1 million after being deceived into authorizing a fraudulent phishing token approval transaction on the Ethereum blockchain.

← Back to Blog