Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Trezor's fulfilment partner ShipMonk exposed 67K customers' personal data that was supposed to have been deleted — highlighting the gap between contractual data-deletion promises and actual vendor practice.
Summary written by editorial AI · Source link below
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.
The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
Editorial Analysis
Framed for the CISO & Security Leaders desk
Trezor's disclosure reveals that a third-party logistics provider retained customer data it was contractually obligated to delete, exposing 67K records — a cautionary tale for vendor data-lifecycle management.
Audit third-party data-processing agreements for data-deletion obligations and verify compliance through periodic evidence requests or technical attestations.
A supplier breach exposed customer data that was contractually supposed to be deleted, highlighting third-party data-governance risk.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Security Desk
- IDScan sued over alleged data breach affecting 153 million drivers3d
- Your Employee’s Password Appeared in an Infostealer Log. Now What?4d
- US and Canadian court data exposed in Thomson Reuters breach4d
- Health data of more than 9.5 million people leaked from Aesto record system5d
- The Agentic SOC – From AI Theater to Real Defense1 Sept