Plan
active
ShipMonk Breach Exposes 67K Trezor Customers' PII Vendor Said It Deleted
- Engineer — Learn: No vulnerability to patch; the salient lesson is that vendor data-deletion attestations cannot be taken at face value — worth reviewing contractual data-retention obligations and requesting evidence (not just assertions) from third-party logistics or fulfillment partners holding customer PII.
- SOC/IR — Skip
- Leader — Plan: This case — a logistics vendor retaining customer data after certifying deletion — is a textbook vendor risk gap; schedule a review of fulfillment and logistics vendors’ data-lifecycle practices this quarter and require documented evidence of deletion rather than self-attestation.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.