Trezor’s latest disclosure reveals that the scope of the data breach previously triggered by the logistics provider ShipMonk has expanded further, with approximately 67,000 additional U.S. customers affected. The compromised records pertain to orders placed between November 2019 and August 2021 and include names, email addresses, phone numbers, home addresses, and order numbers.
Trezor stated that ShipMonk reported the newly exposed data two days ago. The company said that, according to their contract and data policies, these records should have been deleted, and they had received multiple written confirmations from ShipMonk in the past; however, the data was never actually removed.
The number of affected individuals has risen to approximately 80,700.
When Trezor first disclosed the incident in August, it attributed the scope of the impact to a 90-day deletion policy agreed upon with its fulfillment partner. With additional data confirmed, the number of affected customers has increased from 13,689 to approximately 80,700.
The company stated that all affected users are located in the United States, with order placement dates ranging from November 2019 to August 2021, and some records are nearly seven years old.
Risk is concentrated in address and identity information.
Trezor stated that its own systems were not compromised, and hardware devices, private keys, and wallet backups remain unaffected. The greater issue is that the leaked data can be directly linked to confirmed hardware wallet owners and their home addresses.
The company reminds users to be cautious of forged emails, phone calls, and physical letters, and reiterates that wallet backup phrases should never be disclosed to anyone or entered on any website.
In February this year, Trezor and Ledger users both received forged letters. The letters included holographic seals, QR codes, and fabricated executive signatures, demanding users complete a so-called "security check" or lose access to their wallets.
The source of the vulnerability points to Metabase.
The report states that the breach was related to a critical SQL injection vulnerability in the analytics tool Metabase. The vulnerability, disclosed on August 6, allowed attackers to steal credentials from connected databases without authentication. In addition to ShipMonk, Framework and Tally were also affected in the same incident.
Trezor also stated that ShipMonk received a ransom email allegedly from ShinyHunters, though this attribution has not yet been confirmed.
Additional information: Trezor stated that it is accelerating the rollout of anonymous delivery options, including locker pickup, neutral packaging, and generic sender information, to reduce the need for users to provide their home addresses.
