67,000 More Trezor Customers Exposed as Data Breach Widens

CN
Decrypt
Follow
4 hours ago

Another 67,000 Trezor customers had their names, email addresses, phone numbers, home addresses and order numbers exposed in the breach at shipping provider ShipMonk, the hardware wallet maker said on Friday.


All of them are in the U.S., and all placed orders between November 2019 and August 2021, making some of the exposed records close to seven years old. ShipMonk passed on the finding two days ago.



Trezor repeatedly asked for and received written confirmation that those records had been deleted, in line with its contract and data policy, and said it was disappointed to learn they had not been.


When it disclosed the breach in August, the company attributed its limited scope to a 90-day deletion policy it said it had negotiated into its fulfillment partners' terms. That claim now looks considerably weaker. The count has gone from 13,689 to roughly 80,700.


Wallet owners face multiple threats


Trezor's own systems were not breached, and devices, private keys and wallet backups are untouched. The danger is that the records identify confirmed hardware wallet owners at specific front doors. Alongside fake emails, calls and letters, Trezor warned affected customers about risks to their physical security, and repeated that a wallet backup should never be shared or typed into a website.


Owners of both Trezor and rival hardware wallet Ledger were already receiving forged letters in February, printed with holograms, QR codes and forged executive signatures, demanding they activate a fictitious security check or lose access to their wallets.


At the time, cybercrime consultant David Sehyeon Baek told Decrypt that a letter carrying a name and home address signals "we can locate you," and that stolen data stays useful for years because people rarely move or change their numbers.



Myriad: Where does Ethereum price go next? Click to make your prediction.

The intrusion traces to a critical SQL injection flaw in the analytics tool Metabase, disclosed on August 6, which let unauthenticated attackers steal credentials for connected databases. Laptop maker Framework and form builder Tally were caught in the same wave. ShipMonk has reportedly received extortion emails attributed to ShinyHunters, though that attribution remains unconfirmed.


Trezor said it is working to ship anonymous delivery as quickly as possible, an option using locker pickup, neutral packaging and generic sender details so that buyers need not hand over a home address at all.


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink