Trezor Discloses Data Breach via ShipMonk Affecting 67,000 U.S. Customers
Trezor disclosed a data breach at its shipping provider ShipMonk, exposing 67,000 U.S. customers' personal and order details despite assurances of data deletion. The breach involved a zero-day SQL injection flaw in Metabase, exploited by the ShinyHunters gang, leading to customer data leaks and potential social engineering risks.
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.
The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
*** END OF TRANSMISSION ***