Trezor Reports Additional 67,000 U.S. Customer Records Exposed in Data Breach

icon币界网
Share
AI summary iconSummary
Trezor disclosed a security breach affecting 67,000 U.S. customer records, linked to its logistics partner ShipMonk. The exposed data, spanning November 2019 to August 2021, includes names, email addresses, phone numbers, physical addresses, and order details. ShipMonk reported the breach two days ago. Trezor stated that the data should have been deleted per their contract but was not. The total number of affected customers now exceeds 80,700. Trezor’s systems were not compromised, and private keys remain secure. The incident stems from a SQL injection vulnerability in Metabase. The company is transitioning to anonymous shipping to reduce dependence on sensitive personal data. Rising inflation data has accelerated crypto adoption, heightening concerns among investors regarding security breaches.
CoinDesk reports:

Trezor’s latest disclosure reveals that the scope of the data breach previously triggered by the logistics provider ShipMonk has expanded further, with approximately 67,000 additional U.S. customers affected. The compromised records pertain to orders placed between November 2019 and August 2021 and include names, email addresses, phone numbers, home addresses, and order numbers.

Trezor stated that ShipMonk reported the newly exposed data two days ago. The company said that, according to their contract and data policies, these records should have been deleted, and they had received multiple written confirmations from ShipMonk in the past; however, the data was never actually removed.

The number of affected individuals has risen to approximately 80,700.

When Trezor first disclosed the incident in August, it attributed the scope of the impact to a 90-day deletion policy agreed upon with its fulfillment partner. With additional data confirmed, the number of affected customers has increased from 13,689 to approximately 80,700.

The company stated that all affected users are located in the United States, with order placement dates ranging from November 2019 to August 2021, and some records are nearly seven years old.

Risk is concentrated in address and identity information.

Trezor stated that its own systems were not compromised, and hardware devices, private keys, and wallet backups remain unaffected. The greater issue is that the leaked data can be directly linked to confirmed hardware wallet owners and their home addresses.

The company reminds users to be cautious of forged emails, phone calls, and physical letters, and reiterates that wallet backup phrases should never be disclosed to anyone or entered on any website.

In February this year, Trezor and Ledger users both received forged letters. The letters included holographic seals, QR codes, and fabricated executive signatures, demanding users complete a so-called "security check" or lose access to their wallets.

The source of the vulnerability points to Metabase.

The report states that the breach was related to a critical SQL injection vulnerability in the analytics tool Metabase. The vulnerability, disclosed on August 6, allowed attackers to steal credentials from connected databases without authentication. In addition to ShipMonk, Framework and Tally were also affected in the same incident.

Trezor also stated that ShipMonk received a ransom email allegedly from ShinyHunters, though this attribution has not yet been confirmed.

Additional information: Trezor stated that it is accelerating the rollout of anonymous delivery options, including locker pickup, neutral packaging, and generic sender information, to reduce the need for users to provide their home addresses.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.