Trezor announced on Friday (4) that the data leak involving its logistics partner ShipMonk was much larger than initially identified. Another approximately 67,000 customers in the United States had personal information exposed, including data from orders placed between November 2019 and August 2021.
Ver post no X
Combined with the 13,689 customers identified when the incident was disclosed in August, the number of affected people reaches approximately 80,700. The newly found records contained name, email, phone, delivery address, and order number.
The expansion of the case draws attention mainly because of the age of the data. When Trezor announced the leak on August 13, it stated that its policy required partners to delete or anonymize customer information 90 days after delivery, which should limit the number of records available in ShipMonk's systems.
Data should have been deleted
The new discovery shows that customer information from several years ago remained stored. According to Trezor, during its relationship with ShipMonk, the company repeatedly requested data deletion and received written confirmations that this had been done, in accordance with the contract and the retention policy established between the companies.
ShipMonk informed Trezor about the new extent of the incident on September 2. All customers included in this new batch have already been notified by email, according to the hardware wallet maker. Those who did not receive the company's communication would not be among the affected.
Trezor's own systems and its devices were not compromised. The problem lies in the identification data associated with orders, which can facilitate more convincing scams via email, phone, or even physical correspondence.
The company also warned of possible physical security risks, since the exposed records include addresses of people who purchased a cryptocurrency wallet. The guidance is to be wary of contacts requesting personal information and never provide the backup or recovery words of a wallet.
In response to the problem, Trezor is preparing a system of anonymous delivery, with locker pickup, neutral packaging, and automatic deletion of identifiers after delivery. The company plans to make the option available initially in Europe and later in the United States.



