Interestana
Home/News/Trezor: ShipMonk Breach Exposed 67,000 U.S. Customers' Data
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Trezor: ShipMonk Breach Exposed 67,000 U.S. Customers' Data

Trezor: ShipMonk Breach Exposed 67,000 U.S. Customers' Data

Hardware wallet manufacturer Trezor announced on Friday, November 17, 2023, that a data breach affecting its shipping provider, ShipMonk, has impacted an additional 67,000 customers in the United States. This disclosure follows an earlier notification regarding a separate incident. The compromised data includes sensitive customer information such as names, email addresses, phone numbers, shipping addresses, and order numbers. These details were associated with orders placed between November 2019 and August 2021. Trezor has explicitly stated that this breach does not compromise the security of its hardware wallets, emphasizing that private keys and cryptocurrency funds remain protected. The company is working with ShipMonk to understand the full scope of the incident and to implement enhanced security measures.

ShipMonk, a third-party logistics provider, experienced a security incident that led to unauthorized access to its systems. The nature of the breach at ShipMonk has not been fully detailed by either company, but the impact on Trezor's customer base is significant. The exposed data, while not directly related to financial assets stored on Trezor devices, could be used for phishing attacks or other forms of social engineering. Trezor has advised its affected U.S. customers to remain vigilant against potential scams and to monitor their accounts for any suspicious activity. The company is also in the process of notifying all impacted individuals directly, providing them with guidance on how to protect themselves.

This incident highlights the ongoing risks associated with supply chain vulnerabilities in the cybersecurity landscape. Companies that rely on third-party vendors for critical services, such as shipping and logistics, must ensure robust security protocols are in place throughout their entire operational ecosystem. Trezor's commitment to transparency in disclosing the breach, even when originating from a partner, is a crucial step in maintaining customer trust. The company has stated its intention to review and strengthen its vendor risk management processes to prevent future occurrences. The timeframe of the exposed data, spanning nearly two years, suggests a prolonged period of vulnerability within ShipMonk's systems.

Trezor, a well-known provider of hardware cryptocurrency wallets, designs and manufactures devices intended to secure digital assets by keeping private keys offline. Its products are a popular choice for individuals seeking to protect their investments from online threats like hacking and malware. The company's reputation hinges on its ability to provide highly secure solutions. Therefore, any incident that exposes customer data, even indirectly through a service provider, warrants serious attention and a comprehensive response. The company is reportedly cooperating with law enforcement and cybersecurity experts to investigate the ShipMonk breach thoroughly.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next