Particle.news
Download on the App Store

Trezor Breach Grows to About 80,700 After ShipMonk Kept Old Records

Trezor says the expanded exposure shows a vendor failed to delete legacy customer data, increasing the risk of targeted scams and physical threats.

Overview

  • Trezor disclosed Friday that ShipMonk informed the company it found 67,000 additional U.S. order records from November 2019 through August 2021, bringing the known total to roughly 80,700 affected customers.
  • The compromised fields include full names, email addresses, phone numbers, shipping addresses and order numbers, details that let attackers craft convincing phishing, SIM‑swap and doorstep targeting schemes.
  • Trezor says its own systems, devices, private keys and wallet backups were not accessed, so customer crypto holdings were not directly breached.
  • Trezor says ShipMonk repeatedly gave written assurances that older customer data had been deleted but did not purge legacy records, and reporting links the intrusion to a critical SQL‑injection flaw in the Metabase analytics tool that enabled credential theft.
  • Trezor has emailed all newly identified customers, is fast‑tracking anonymous delivery and other mitigations, and security analysts warn the dataset could be sold or used for extortion, prolonging risk to affected people and their homes.