Trezor has disclosed that the data breach at its shipping provider ShipMonk is far larger than initially reported, with an additional 67,000 U.S. customers now known to have had personal information exposed. The hardware wallet maker said the newly identified records cover orders placed between November 2019 and August 2021, meaning some compromised data is nearly seven years old.
When Trezor first disclosed the incident last month, it said approximately 13,689 customers were affected. Of those, 12,742 had names, emails, phone numbers, and shipping addresses exposed, while 1,947 had more limited information compromised. The latest update brings the known total to more than 80,000 customers. Trezor said it had repeatedly requested and received written assurances from ShipMonk that the data had been deleted in line with its contract and data policy. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.
Trezor emphasized that its own systems were not compromised and that devices, private keys, and wallet backups remain secure. However, the exposure of names, emails, phone numbers, home addresses, and order numbers creates serious phishing and physical security risks. The company warned affected users to be cautious of fake emails, fraudulent phone calls, and physical letters.
The breach has been linked to a critical SQL injection flaw in the analytics tool Metabase disclosed on August 6, which also affected laptop maker Framework and form builder Tally. Trezor said it is working to offer anonymous delivery with locker pickup, neutral packaging, and generic sender details as quickly as possible. Owners of both Trezor and rival hardware wallet Ledger previously received forged letters in February demanding fictitious security checks, and experts warn that stolen address data remains useful to criminals for years.