Hardware crypto wallet provider Trezor says the personal information of nearly 14,000 people was compromised in a data breach.
The incident, it says, did not involve Trezor’s systems but rather its third-party shipping provider, ShipMonk. Trezor was notified of the attack on August 10.
Customers in the US, the UK, Sweden, Colombia, Brazil, Italy, and Portugal who placed orders between May 10 and August 8 were affected.
“We’re extremely sorry to inform our community that customer personal information, including full names, phone numbers, email addresses, and shipping addresses, has been accessed by an unauthorized actor during this breach,” Trezor says in a notice.
Hackers stole the names, addresses, email addresses, and phone numbers of 11,742 customers, as well as the names, cities, and email addresses of 1,947 customers. Trezor shared the information with ShipMonk for order delivery purposes.
“The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy),” the company says, but notes that for the 1,947 customers with partial exposure, older orders might have been accessed as well.
“To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts,” the company says.
Trezor notified all impacted customers via email and advised them to be wary of suspicious communication that requests personal information or prompts for immediate action.
The company says it is in direct contact with ShipMonk to establish an exact timeline of events and determine the full scope of the data breach.
ShipMonk reportedly notified customers that hackers accessed customer data by exploiting a vulnerability in Metabase. The targeted bug is likely the SQL injection zero-day that Metabase patched last week.
The notorious extortion group ShinyHunters claimed responsibility for an attack on Metabase. On Wednesday, the group leaked data allegedly stolen from the data analytics solutions provider.
ShipMonk has yet to acknowledge the incident publicly. It is unclear how many companies might have been affected, whether other individuals’ personal information was stolen, and who was behind the attack.
SecurityWeek has emailed ShipMonk for a statement on the data breach and will update this article if the company responds.
Related: Ceva Logistics Operations Disrupted by Cyberattack
Related: Corporate Data Stolen in Levi Strauss Cyberattack
Related: 3.8 Million Impacted by Unlimited Technology Systems Data Breach
Related: 311,000 Impacted by Brown Health Medical Group-MA Data Breach