Hardware wallet manufacturer Trezor has disclosed that a previously announced data breach is more extensive than initially reported.

The Prague, Czech Republic-based company revealed on Friday that an additional 67,000 U.S. customers experienced exposure of their personal information, including names, email addresses, phone numbers, shipping addresses, and order details. This data was reportedly accessed through orders placed between November 2019 and August 2021.

Initially announced in August, Trezor had identified a breach impacting 11,742 customers in the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal, with similar types of personal data compromised.

The company further reported an additional 1,947 individuals had their names, cities, and email addresses exposed in the incident. Trezor attributed the breach to unauthorized access at its third-party fulfillment partner, ShipMonk, and expressed serious concerns over the fulfillment provider’s handling of customer data.

In its statement, Trezor emphasized that it repeatedly requested and received written confirmation from ShipMonk regarding the deletion of customer data, in accordance with contractual obligations and policies. However, the company expressed disappointment that the data remained stored in ShipMonk’s systems despite these assurances.

Trezor and ShipMonk did not immediately respond to requests for comment from Bitcoin Magazine.

The initial breach, announced in August, stemmed from unauthorized access to ShipMonk’s systems containing customer records. Trezor confirmed it had directly contacted all affected customers to inform them of the incident.

Trezor’s parent company, SatoshiLabs, had previously stated it was conducting an investigation into the matter. As a leading provider of Bitcoin hardware wallets and cryptocurrency storage solutions, Trezor serves a significant user base reliant on its security measures.

This incident echoes past cybersecurity challenges in the crypto industry, including a 2020 breach at hardware manufacturer Ledger that exposed over 1 million email addresses and 10,000 customers’ personal data. Similar risks emerged in early 2024 when a breach at Global-e, Ledger’s payment processor, compromised customer information stored in the company’s cloud infrastructure.

Source link

Exit mobile version