A shocking data breach has left over 67,000 U.S. customers of ShipMonk exposed, and it gets even worse – their sensitive information was allegedly deleted from the compromised system, only to resurface in a cybersecurity report. The incident raises questions about the true nature of data deletion and highlights the ongoing struggle with identity exposure.
Trezor, a leading manufacturer of hardware wallets, claimed that its customers’ data was erased as part of an investigation into ShipMonk’s security practices. However, researchers from the cybersecurity firm found a trove of sensitive information, including customer names, email addresses, phone numbers, and physical addresses. The breach is attributed to a vulnerability in ShipMonk’s API, which allows malicious actors to access and manipulate data.
ShipMonk is an order fulfillment platform that helps e-commerce businesses streamline their logistics operations. Trezor uses ShipMonk for order management and shipping. In this case, the compromise of ShipMonk’s system led to unauthorized access to sensitive customer information, exposing them to potential phishing, social engineering attacks, or even identity theft.
The issue at hand is not just about data breaches; it’s also about the concept of “data deletion.” Many companies claim that they delete sensitive data from their systems once an investigation or a security incident has been resolved. However, in this case, researchers were able to recover deleted records from a backup system, demonstrating that true data erasure is often not as straightforward as claimed.
This breach highlights the ongoing struggle with identity exposure and the need for more robust security measures. Companies must prioritize protecting sensitive customer information and be transparent about their security practices. Additionally, customers should be aware of the risks associated with online transactions and take steps to safeguard their identities. A strong password manager, two-factor authentication, and regular monitoring of financial statements can go a long way in preventing potential identity theft.
In light of this breach, it’s essential for individuals to stay vigilant about protecting their sensitive information. If you’re a ShipMonk customer or use similar services, take the time to review your account settings and ensure that you have enabled robust security measures. Additionally, be cautious when clicking on links or providing personal information over email, as attackers may try to exploit this breach to launch targeted attacks.
Source: The Hacker News — 2026-09-05