THE hardware crypto wallet provider Trezor reported a data breach affecting nearly 14,000 customers, which involved personal information being compromised through its third-party shipping provider, ShipMonk, rather than Trezor's own systems. The affected customers, from countries including the US, UK, Sweden, and Brazil, had their names, email addresses, phone numbers, and shipping information accessed.
Trezor was informed of the breach on August 10 and has implemented a 90-day data storage policy to limit exposure. Customers are advised to be cautious of potential phishing attempts. ShipMonk is currently under investigation for exploiting a vulnerability in Metabase, with the extortion group ShinyHunters claiming responsibility for the exploit.