AUTO-UPDATED

Trezor Supply Chain Breach Now Impacts 81,000 Customers

Hardware wallet manufacturer Trezor confirmed that a data breach at its shipping partner, ShipMonk, exposed the personal information of 67,000 additional customers, significantly exceeding initial incident estimates.

Key Points

  • The breach exposed names, email addresses, phone numbers, shipping addresses, and order details for customers between November 2019 and August 2021.
  • The updated victim count represents a 479% increase over the 14,000 individuals originally reported by the company on August 13.
  • Trezor stated that ShipMonk failed to delete customer data as required by their contract and data minimization policies.
  • The company is currently evaluating potential legal action against the logistics provider following the security failure.
  • Trezor is accelerating plans for anonymous delivery options and advises customers to use parcel lockers or PO boxes to protect their privacy.

Why it Matters

This incident highlights the significant security risks posed by third-party logistics providers when handling sensitive customer data. It serves as a reminder that even companies with strong internal security can be compromised through supply chain vulnerabilities, potentially exposing users to targeted phishing and physical security threats.
Infosecurity Magazine Published by Phil Muncaster
Read original