Users exposed by Trezor breach grows sixfold after supposedly deleted shipping logs are found

Hardware wallet maker Trezor says a breach at logistics provider ShipMonk exposed contact and order data for another approximately 67,000 U.S. customers after years-old records remained in the vendor's systems despite written deletion assurances.
The Sept. 4 update expands an incident Trezor initially said affected 13,689 people. The two disclosed groups imply a total of roughly 80,689, although Trezor has not issued a single combined figure or published underlying data showing whether the groups overlap. Its use of “another” indicates that it considers the new records additional to the original cohort.
The newly disclosed records cover U.S. orders from November 2019 through August 2021 and include names, email addresses, phone numbers, shipping addresses and order numbers. The data can connect an identifiable person and physical location with a hardware-wallet purchase, creating risks beyond a conventional email leak.
Old data outlived a 90-day policy
When Trezor first disclosed the breach on Aug. 13, it counted 11,742 customers with full exposure and 1,947 with partial exposure. Trezor's Aug. 13 account said older order data had already been deleted. An Aug. 14 clarification acknowledged that some partially exposed records included older orders.
… Continue reading the full article at the original source below.


