Trezor says data breach affects another 67K US customers

摘要:An additional 67,000 US users who ordered Trezor wallets between 2019 and mid-2021 may have been exposed to the shipping providers data breach, creating pathways to phishing attacks.

The impact of hardware wallet provider Trezors data breach was larger than initially estimated, expanding to an additional 67,000 US customers.

The breach may endanger more US users who ordered between November 2019 and August 2021, Trezor said in a Friday X post, citing the latest update from its shipping provider, ShipMonk.

These customers had their full details exposed, including name, email, number, shipping address and order specifics. Trezor blamed the shipping provider for not deleting the data from these orders, despite saying it had received written assurances from ShipMonk.

While Trezor systems were not compromised, the data breach may threaten the digital asset holdings of the 67,000 customers, as attackers may use the information for phishing attacks impersonating Trezor, in a bid to steal users seed phrases controlling their wallets.

In August, Trezor initially estimated that only 14,000 users had their data exposed through the shipping provider. Trezor reported in January 2024 that about 66,000 users were at risk of phishing attacks if they had contacted the companys support team since December 2021.

Phishing attacks and social engineering don‘t require exploiting code vulnerabilities. Still, these impersonation-based scams drove the majority of the crypto industry’s losses in the first quarter of the year, accounting for $306 million of the total $482 million lost, according to blockchain security company Hacken.

In July, a crypto investor lost nearly $1 million after signing a malicious phishing token approval transaction on Ethereum.

免责声明

本文观点仅代表作者个人观点,不构成本平台的投资建议,本平台不对文章信息准确性、完整性和及时性作出任何保证,亦不对因使用或信赖文章信息引发的任何损失承担责任
上一篇

WikiBit交易所跑路风险榜第17期BigONE:李笑来、老猫的“币圈活化石”,怎么活成了“监管黑名单”?

下一篇

CFTC申请驳回关于加密货币永续期货的CME诉讼