14,000 Trezor customers affected by ShipMonk data breach

14,000 Trezor customers affected by ShipMonk data breach

Hardware crypto wallet provider Trezor says nearly 14,000 people’s personal information was compromised in a data breach.

Trezor’s systems were not involved in the incident, but rather the third-party provider ShipMonk. Trezor was informed of the attack on August 10th.

Customers in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal who placed orders between May 10 and August 8 were affected.

“We are very sorry to inform our community that during this breach, an unauthorized actor accessed customers’ personal information, including full names, phone numbers, email addresses, and shipping addresses,” Trezor said in a comment observe.

Hackers stole the names, addresses, email addresses and phone numbers of 11,742 customers and the names, cities and email addresses of 1,947 customers. Trezor shared the information with ShipMonk for the purpose of order delivery.

“The breach is limited due to Trezor’s strict 90-day data retention policy (we were also able to negotiate the same terms with fulfillment partners who follow the same policies),” the company says, but notes that the 1,947 customers with partial compromise may also have had older orders accessed.

Advertising. Scroll to continue reading.

“To be clear, our systems have not been compromised and your Trezor device is secure, but affected customers may be the target of more sophisticated phishing attempts,” the company says.

Trezor notified all affected customers via email and advised them to be cautious of suspicious communications requesting personal information or requesting immediate action.

The company says it is in direct contact with ShipMonk to establish an accurate timeline of events and determine the full extent of the data breach.

ShipMonk allegedly Notified customers that hackers accessed customer data by exploiting a vulnerability in Metabase. The target bug is likely the zero-day SQL injection that Metabase patched last week.

The infamous extortion group ShinyHunters claimed responsibility for an attack on Metabase. On Wednesday, the group leaked data that was allegedly stolen from the data analytics solutions provider.

ShipMonk has not yet publicly acknowledged the incident. It’s unclear how many companies may have been affected, whether other people’s personal information was stolen and who was behind the attack.

Safety Week has emailed ShipMonk for comment on the data breach and will update this article if the company responds.

Related: Ceva logistics operations disrupted by cyber attack

Related: Company data stolen in Levi Strauss cyberattack

Related: 3.8 million people have been affected by data breaches at Unlimited Technology Systems

Related: 311,000 affected by Brown Health Medical Group-MA data breach

Leave a Reply

Your email address will not be published. Required fields are marked *