CuraSec

Plan active

ShipMonk Breach Exposes 67K Trezor Customers' PII Vendor Said It Deleted

2026-09-06 14:08 UTC · The Hacker News · read the source ↗ #vendor-breach#supply-chain#data-exposure
  • Engineer — Learn: No vulnerability to patch; the salient lesson is that vendor data-deletion attestations cannot be taken at face value — worth reviewing contractual data-retention obligations and requesting evidence (not just assertions) from third-party logistics or fulfillment partners holding customer PII.
  • SOC/IR — Skip
  • Leader — Plan: This case — a logistics vendor retaining customer data after certifying deletion — is a textbook vendor risk gap; schedule a review of fulfillment and logistics vendors’ data-lifecycle practices this quarter and require documented evidence of deletion rather than self-attestation.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.