Trezor said that the impact of the data breach related to the charging provider was greater than initially estimated, after it emerged that an additional 67,000 customers in the United States were affected by the incident.
According to an update the company published on Friday on the X platform, the breach may affect users who ordered products between November 2019 and August 2021, based on the latest update it received from the ShipMonk shipping provider.
Trezor clarified that the exposed data included the name, email address, phone number, shipping address, and order details. It added that the problem stemmed from the shipping provider’s failure to delete this data, despite the company saying it had received written assurances that it had been removed.
Trezor emphasized that its own systems were not breached, but the real danger lies in how this information could be exploited later. Attackers could use it in phishing campaigns impersonating Trezor, with the aim of deceiving users into handing over their wallet recovery phrases, the keys that grant control of digital assets.
The company had estimated in August that the number of affected people did not exceed 14,000 users, before significantly raising the current estimate. It also said it had warned in January 2024 that around 66,000 users could be vulnerable to phishing attacks if they had contacted the support team since December 2021.
These developments come at a time when phishing and social engineering attacks continue to prove effective in the cryptocurrency sector, as these methods do not require exploiting software vulnerabilities, but instead rely on impersonation and the exploitation of trust and personal data.
For affected users, the practical message is clear: any communication claiming to be from Trezor should be treated with extreme caution, and the recovery phrase should not be shared or entered into any untrusted website or form. Messages received should also be verified only through official channels, and any unusual requests related to the account, shipping, or support should be reviewed.
This incident shows that a breach involving shipping data can quickly turn into a direct threat to digital assets, even when the company’s technical infrastructure itself remains intact.
#الأمن_السيبراني #العملات_الرقمية $TREZOR
