Crypto Prices

Trezor alerts 67,000 US customers of expanded data breach risks

16 hours ago
1 min read
7 views

Trezor Data Breach Update

Trezor has revealed that the fallout from a data breach linked to its shipping partner has escalated significantly, now implicating an additional 67,000 customers in the United States. This development raises concerns about the heightened risk of phishing scams and social engineering tactics aimed at these users.

Initial Estimates and New Findings

Initially, the hardware wallet manufacturer estimated that the breach had compromised the information of approximately 14,000 individuals; however, new evidence from ShipMonk, the shipping company involved, indicates that any U.S. customers who placed orders between November 2019 and August 2021 are now vulnerable. Details such as names, email addresses, phone numbers, shipping locations, and order specifics were all part of the data exposed.

Risks and Implications

Despite Trezor’s own systems remaining secure, the company is wary of the potential risks that this stolen information poses, as malicious actors could exploit it to impersonate Trezor and initiate phishing assaults to steal users’ wallet seed phrases — critical for accessing their digital assets. In January 2024, Trezor noted a specific risk for around 66,000 of its customers who reached out to customer support since December 2021 due to the incident.

Rising Phishing Threats

This concern comes against a backdrop of rising phishing attacks within the cryptocurrency space, which have proved to be a significant threat, leading to massive financial losses. According to blockchain security firm Hacken, such impersonation-based scams resulted in $306 million in losses out of a total of $482 million experienced in the first quarter of the year. Incident reports, including a case in July where an investor lost nearly $1 million due to a phishing token approval on Ethereum, underscore the increasing scale of these threats.

Conclusion

Trezor’s communication via a post on X reflects a growing urgency to address these vulnerabilities and assist affected customers as they navigate the risks stemming from the breach and potential future attacks.

Popular