Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Summary
Hardware wallet manufacturer Trezor has revealed that a breach at its shipping provider, ShipMonk, has exposed the data of an additional 67,000 U.S. customers. The compromised information includes names, emails, phone numbers, shipping addresses, and order numbers for orders placed between November 2019 and August 2021. Trezor emphasized that this breach does not compromise the security of their hardware wallets.
IFF Assessment
This breach exposes sensitive customer data, which can be used by threat actors for further attacks, making it bad news for defenders.
Defender Context
This incident highlights the critical importance of third-party risk management for organizations. Defenders need to ensure that their vendors and service providers have robust security measures in place to prevent data breaches. This breach could lead to phishing campaigns or identity theft targeting the affected customers.