14K Trezor Users Exposed to Phishing via ShipMonk Breach

Key Takeaways

Trezor disclosed that personal data for approximately 14,000 customers was leaked through logistics partner ShipMonk. While hardware security remains intact, compromised contact details significantly elevate targeted phishing risks for affected users.

Woofun AI reports that a data exposure incident involving logistics partner ShipMonk has placed approximately 14,000 Trezor customers at risk of sophisticated phishing attacks. The breach stems from a compromise in the shipping provider's systems rather than Trezor's own infrastructure, highlighting a critical vulnerability in the supply chain. This event underscores the growing threat of third-party data leaks impacting hardware wallet security.

The compromised dataset includes individuals who received products in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and Aug. 8. Per Woofun AI, 11,742 customers had their name, physical address, phone number, and email address exposed. A separate group of 1,947 users saw their name, city, and email address breached, creating a detailed profile for potential social engineering campaigns.

Trezor explicitly stated that the Trezor device is secure and its internal systems were not compromised.

However, scammers can leverage the leaked information to send fake emails, make fake phone calls, or dispatch fraudulent letters. These actors may impersonate banks, crypto exchanges, or even Trezor itself to deceive victims into revealing sensitive credentials or transferring funds.

This incident follows a similar report in January 2024, where 66,000 users were warned of phishing risks after contacting support since December 2021. The broader threat landscape includes scammers using physical letters, text messaging, emails, and phone calls. Tactics often involve impersonating family members in distress or authorities demanding repayment of fake debt, marking a persistent evolution in social engineering methods.

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions