Trezor announced that another 67,000 US customers had their personal information exposed through a data breach at ShipMonk, the company's shipping provider. This disclosure expands the total number of affected customers to over 80,000 since the breach was first reported in August.
The newly identified customers placed orders between November 2019 and August 2021. Exposed information includes names, email addresses, phone numbers, shipping addresses, and order numbers. Some of the compromised records were nearly seven years old.
Trezor said it had repeatedly requested that ShipMonk delete the information and received written assurances that the data had been securely removed. The discovery that records were still retained contradicts those assurances.
An earlier disclosure identified 13,689 affected customers, with 11,742 having their names, contact details, and shipping addresses exposed. The remaining 1,947 had fewer compromised details. Trezor said it contacted all newly identified customers by email two days before publishing its latest update.
Security and Risk Assessment
Trezor stated that its own systems were not compromised and customer wallet backups and cryptocurrency holdings remain secure. The attacker did not have direct access to customer crypto assets.
However, the exposed personal information poses significant risks. Stolen data including customer names, orders, and contact information could be used to create convincing phishing scams impersonating Trezor through emails, calls, or letters.
The exposed shipping addresses present an additional concern, as they could identify locations where hardware wallets are stored, creating potential physical security risks.
Customer Guidance and Company Response
Trezor advised customers never to disclose their wallet backup or enter it on any website, regardless of who requests it. The company stated that customers who did not receive notification emails are not believed to be affected.
Trezor said it is working to introduce anonymous delivery options, which would allow customers to purchase devices while sharing less personal information.


