Trezor data breach exposes 67,000 additional US customers
Hardware wallet maker Trezor revealed its recent data leak extends to 67,000 new American buyers ordered between late 2019 and mid-2021, surpassing its own earlier estimate of roughly half that number.
Trezor announced a data breach affecting another 67,000 US customers who placed orders from November 2019 through August 2021. The vendor cited ShipMonk as the source, stating the provider failed to delete personal information despite receiving written assurances that cleanup had occurred. Trezor confirmed its own systems remained secure, yet the leaked data includes names, email addresses, phone numbers, shipping addresses, and order specifics for these users. Security experts warn such exposure allows attackers to impersonate the company in phishing campaigns targeting seed phrases and private keys. In August, Trezor estimated only 14,000 accounts were compromised via the shipping chain. A January 2024 report adjusted this figure to approximately 66,000 users potentially targeted by social engineering attacks rather than code exploits. Hacken data indicates impersonation scams caused $306 million of the total $482 million lost in crypto security losses during Q1 this year.