Trezor, a Prague-based hardware wallet manufacturer, announced Friday that a data breach disclosed last month exposed significantly more customers than previously reported. An additional 67,000 U.S. customers had their names, emails, phone numbers, shipping addresses, and order numbers leaked from transactions made between November 2019 and August 2021.
The company initially reported in August that 11,742 customers across the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal had been compromised, with names, emails, phone numbers, and shipping addresses exposed. A subsequent update revealed another 1,947 customers had their names, cities, and emails exposed.
Trezor attributed the expanded breach to its third-party fulfillment partner, ShipMonk, which the company said experienced unauthorized access to customer data systems. In its Friday statement, Trezor stated that ShipMonk had provided repeated written assurances confirming deletion of customer data in accordance with contract terms and data policies.
"We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems," Trezor wrote in the announcement.
The company disclosed that it had directly emailed all affected customers about the breach. Trezor's parent company, SatoshiLabs, indicated it was investigating the incident.
Trezor is among the widely used Bitcoin hardware wallet solutions and supports storage of additional cryptocurrencies. The breach adds to a pattern of data exposure affecting cryptocurrency hardware manufacturers: in 2020, hardware wallet maker Ledger experienced unauthorized access to its e-commerce and marketing database, compromising over 1 million email addresses and personal contact data from nearly 10,000 customers. Earlier this year, customers reported a data breach at Global-e, Ledger's payment partner, that exposed sensitive customer information from its cloud systems.


