Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageSecurity Desk
Security

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Trezor's fulfilment partner ShipMonk exposed 67K customers' personal data that was supposed to have been deleted — highlighting the gap between contractual data-deletion promises and actual vendor practice.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.

The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

Editorial Analysis

Framed for the CISO & Security Leaders desk

Why it matters

Trezor's disclosure reveals that a third-party logistics provider retained customer data it was contractually obligated to delete, exposing 67K records — a cautionary tale for vendor data-lifecycle management.

What to do

Audit third-party data-processing agreements for data-deletion obligations and verify compliance through periodic evidence requests or technical attestations.

Board brief

A supplier breach exposed customer data that was contractually supposed to be deleted, highlighting third-party data-governance risk.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Security Desk