Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageSecurity Desk
Security

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Trezor's fulfilment partner ShipMonk exposed 67K customers' personal data that was supposed to have been deleted — highlighting the gap between contractual data-deletion promises and actual vendor practice.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.

The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

Editorial Analysis

Framed for the Compliance & GRC desk

Why it matters

Data that should have been deleted under contractual terms was retained and then breached — a clear failure in data-lifecycle governance with GDPR and contractual implications.

What to do

Review data-retention clauses in processor agreements and implement automated verification or deletion-confirmation workflows for sensitive personal data.

Board brief

A supplier breach exposed customer data that was contractually supposed to be deleted, highlighting third-party data-governance risk.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Security Desk