Hardware wallet manufacturer Trezor is notifying tens of thousands of additional customers regarding an expanded data breach stemming from its former shipping partner, ShipMonk.
According to Trezor, ShipMonk reported on September 2 that order records dating from November 2019 through August 2021 remained in its systems and were impacted by the same incident initially disclosed in August.
The newly exposed records involve approximately 67,000 U.S. customers and include full names, email addresses, phone numbers, shipping addresses, and order numbers.
Trezor expressed frustration that ShipMonk failed to delete the records despite repeated written assurances tied to contractual obligations and a 90-day data retention policy. Trezor stated that it had consistently received confirmation over the years that past customer data had been removed.
Trezor confirmed that all affected individuals have received direct email notices from a specified support address, and customers who did not receive an email are not part of the expanded breach. The company also emphasized that the incident occurred entirely within ShipMonk's infrastructure, and Trezor's own systems and hardware wallets remain uncompromised.
Following the discovery, Trezor warned impacted customers of heightened phishing threats and physical security risks resulting from the leaked personal information. This latest disclosure follows a smaller set of recent-order exposures initially announced on August 13.


