Trezor has disclosed that a data breach tied to its shipping provider, ShipMonk, now includes information connected to an additional 67,000 customers. The newly identified records expand the scope of the incident beyond previous disclosures, and the affected data varieties include personal identifiers and order details that could be used in downstream social engineering attempts.
According to the company, the newly exposed records cover customer information dating from 2019 through 2021. This temporal span extends beyond the 90-day retention window that was described in earlier communications, suggesting a longer period during which personal data may have been exposed as part of the breach. The data elements identified in the affected records include names, email addresses, phone numbers, shipping addresses, and order numbers, all of which could be leveraged in targeted scams or phishing campaigns.
The company notes that the newly affected cohort comprises US customers, heightening concerns about the potential for fraud and impersonation within a domestic user base. While the breach is linked to the shipping partner's data handling, the exposure nonetheless touches customers who interacted with Trezor for hardware wallet purchases and related services. The data mix—combining contact details with order identifiers—can enable attackers to craft credible messages that appear to originate from the retailer or its logistics partner.
Experts and observers typically underscore that data exposures of this kind can widen the risk landscape for users, especially when identifiers such as names, emails, and phone numbers are paired with order information. In the wake of the disclosure, the breach underscores the ongoing challenge for hardware-wallet ecosystems to monitor third-party logistics connections and to review data-sharing arrangements for potential vulnerabilities. The company has not disclosed any details about whether customer funds or wallet seeds were compromised, focusing the risk assessment on the exposure of personal data and the associated phishing risk.
Coverage of the release indicates that the breadth of the breach has prompted renewed attention to data governance practices across partner networks. While the incident centers on a shipping provider, the ripple effects touch the customer base of the wallet maker, reinforcing the need for clear notices about data exposure timelines, the types of data involved, and the steps recommended for users to monitor for suspicious activity. The situation remains under review as investigators and the affected company verify the scope of the breach and the precise data elements involved across different batches of records.