- Trezor revealed an additional 67,000 US users were affected in its mailing partner breach, raising the total to over 80,000.
- The company says ShipMonk repeatedly gave written assurance that old user data was deleted, but that policy was never enforced.
- Trezor claims it had “no reason to expect” further leaks because of ShipMonk’s repeated assurances.
Trezor is “terribly sorry” after revealing today that another 67,000 US users were exposed in last month’s mailing partner breach, bringing the total affected to over 80,000. The hardware wallet company initially disclosed in August that the personal details of 13,689 customers had been leaked after bad actors infiltrated ShipMonk‘s systems.
At the time, Trezor downplayed the incident by claiming its 90-day data deletion policy, which partners followed, helped mitigate the leak. However, Trezor now admits that policy was never enforced and the data was never deleted.
“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data,” Trezor claimed. It added, “We’re terribly sorry to everyone affected.”
Trezor told Protos that on August 10, ShipMonk reported an initial leak covering orders within the last 90 days. On September 2, ShipMonk revealed the breach actually extended back to 2019 and 2021.
When asked why it took ShipMonk to disclose the full scope, Trezor said it had “no reason to expect it” thanks to ShipMonk‘s repeated assurances. Such leaks can enable criminals to target crypto users with tailored attacks.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
