The personal information of nearly 14,000 Trezor customers has been compromised due to a data breach involving their third-party shipping partner, ShipMonk, as reported by Trezor. The breach, which did not affect Trezor’s own systems, was disclosed to the company on August 10.
Details of the Data Breach
Affected customers are from several countries, including the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, who made purchases between May 10 and August 8. Trezor has expressed deep regret for the incident, confirming that the breach involved unauthorized access to full names, phone numbers, email addresses, and shipping details.
In total, hackers obtained the personal information of 11,742 customers, alongside partial data from an additional 1,947 customers. This information was shared with ShipMonk solely for delivery purposes.
Impact and Response
Trezor has assured users that their devices remain secure, emphasizing that only personal data was exposed. However, the company warns that affected customers could face sophisticated phishing attacks. To mitigate the risk, Trezor has contacted all impacted individuals via email, advising vigilance against any suspicious communications.
Despite the breach, Trezor’s strict data retention policy, which limits storage to 90 days, helped contain the extent of the exposure. However, they noted that older orders of the partially affected customers might have been accessed.
Investigation and Security Measures
Currently, Trezor is working closely with ShipMonk to establish a detailed timeline and understand the breach’s full scope. ShipMonk reportedly communicated to its customers that the breach exploited a vulnerability in Metabase, potentially linked to a recently patched SQL injection zero-day flaw.
The attack has been claimed by the notorious ShinyHunters group, who allegedly leaked data from Metabase. While ShipMonk has not publicly addressed the breach, investigations continue to assess the broader impact on other companies and individuals.
As the situation develops, SecurityWeek has reached out to ShipMonk for additional comments and will provide updates as new information becomes available.
