
Trezor says a logistics provider's retained records exposed contact and order data for 67,000 additional U.S. customers, expanding the incident sixfold.
Hardware wallet maker Trezor says a breach at logistics provider ShipMonk exposed contact and order data for roughly 67,000 additional U.S. customers. The Sept. 4 update expands an incident Trezor initially said affected 13,689 people.
The two disclosed groups imply a total of about 80,689 affected customers, though Trezor has not issued a single combined figure. Its use of "another" indicates the new records are separate from the original cohort.
The newly disclosed records cover U.S. orders from November 2019 through August 2021. They include names, email addresses, phone numbers, shipping addresses and order numbers. The data can link an identifiable person and physical location to a hardware-wallet purchase, creating risks beyond a typical email leak.
When Trezor first disclosed the breach on Aug. 13, it counted 11,742 customers with full exposure and 1,947 with partial exposure. The Aug. 13 statement said older order data had already been deleted. The Sept. 4 update reverses that understanding. Trezor said it repeatedly requested and received written assurances from ShipMonk confirming deletion, yet records from 2019 to 2021 remained. The company's published delivery-data policy says customer details should be deleted from both its own and its fulfillment partner's systems after 90 days, with exceptions for ongoing order issues. The assurance letters have not been made public.
BleepingComputer reported that a ShipMonk notification attributed the original unauthorized access to a vulnerability in analytics platform Metabase. Metabase said the August zero-day could create a session tied to an administrator account and allow bulk table downloads. Once the provider incident was reassessed, the retained historical data expanded the number of Trezor customers known to be exposed.
The breach did not reach Trezor's wallet systems. The company said its systems and products were not compromised and its devices remained secure. The exposed fields were contact and order data, not recovery seeds or private keys.
Trezor warned that the information could support convincing scam emails and fraudulent calls, with potential physical targeting as a secondary risk. The Sept. 4 update did not identify a confirmed downstream attack caused by this dataset, so those outcomes remain risks rather than documented consequences.
Trezor said it emailed every newly affected customer directly. Anyone who did not receive its incident notice was not affected. It urged customers never to share a wallet backup or enter it on a website.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.