Interestana
Home/News/Trezor Reports Additional 67K US Customers Affected by Breach
CoinTelegraph3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Trezor Reports Additional 67K US Customers Affected by Breach

Trezor Reports Additional 67K US Customers Affected by Breach

Trezor reported on March 19, 2024, that an additional 67,000 United States customers have been affected by a data breach originating from its third-party shipping provider. This incident exposes these users to an increased risk of phishing attacks and social engineering scams. The breach specifically compromised customer data that was shared with the shipping partner for the purpose of delivering Trezor hardware wallets. Trezor, a company known for its cryptocurrency hardware wallets, aims to provide secure storage solutions for digital assets, making the security of its customer data paramount.

The initial breach was disclosed by Trezor on January 24, 2024, when it revealed that a subset of its customer base had their data exposed due to a vulnerability at a shipping partner. At that time, Trezor stated that approximately 164,000 customers were impacted. The subsequent announcement on March 19, 2024, indicates that the scope of the breach is larger than initially understood, bringing the total number of affected US customers to over 231,000 (67,000 new + 164,000 initial). The compromised information is understood to include customer names, email addresses, and physical mailing addresses, which are all critical components for targeted phishing and social engineering campaigns. Trezor has emphasized that no cryptocurrency funds or private keys stored on its hardware wallets were compromised in this incident, as the breach was limited to shipping and customer contact information.

In response to the expanded breach notification, Trezor has advised all affected customers to remain vigilant against potential fraudulent communications. The company recommends that users scrutinize any unsolicited emails, messages, or calls that appear to be from Trezor or related entities. Users should verify the authenticity of any communication by independently navigating to Trezor's official website rather than clicking on links provided in suspicious messages. Furthermore, Trezor has stated it is working closely with its shipping provider and relevant authorities to investigate the full extent of the breach and to implement enhanced security measures to prevent future occurrences. The company's commitment to user security is a cornerstone of its brand, as it operates in the highly sensitive cryptocurrency security sector. Hardware wallets like those produced by Trezor are designed to safeguard private keys offline, offering a significant security advantage over software wallets or exchange-based storage, but their effectiveness relies on the overall security of the user's interaction with the company and its partners.

This incident highlights the persistent cybersecurity challenges faced by companies that rely on third-party vendors for critical operational functions, such as shipping and logistics. The interconnected nature of supply chains means that a vulnerability in one partner can have cascading effects on multiple businesses and their customer bases. Trezor's proactive communication, despite the expanded scope of the breach, is crucial for enabling its customers to take necessary precautions. The company's advice to exercise caution and verify communications is standard best practice for mitigating the impact of phishing and social engineering attacks, which often leverage personal data to appear more credible. The ongoing investigation aims to provide more clarity on the exact methods used by the attackers and the specific vulnerabilities exploited within the shipping provider's systems.

Original source — read the full reporting at the publisher:

Read on CoinTelegraph

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next