- Trezor says approximately 67,000 additional U.S. customers were affected by a breach at shipping provider ShipMonk, significantly expanding the previously disclosed incident.
- The newly identified records include names, emails, phone numbers, shipping addresses and order numbers from customers who placed orders between November 2019 and August 2021.
- Trezor says its own systems and hardware wallets were not compromised, but affected customers should remain alert for phishing, fraudulent calls, physical letters and other security risks.
Trezor has revealed that a data breach involving shipping provider ShipMonk affected approximately 67,000 more U.S. customers than previously disclosed.
ShipMonk informed Trezor on Sept. 2 that the incident was larger than initially reported and included historical order information from customers who placed orders between November 2019 and August 2021.

The newly identified records contain names, email addresses, phone numbers, shipping addresses and order numbers.
Trezor said it has contacted all customers affected by the latest disclosure.
Trezor Says Data Should Have Been Deleted
Trezor said it had repeatedly instructed ShipMonk to delete customer information throughout their relationship.
According to the hardware wallet company, ShipMonk provided written confirmation that the information had been removed in accordance with contractual requirements, data policies and previous communications.
Trezor said it was “very disappointed” to discover that the information had remained in ShipMonk’s systems despite those assurances.
When the breach was initially disclosed on Aug. 13, Trezor said 11,742 customers had names, emails, phone numbers and shipping addresses exposed.
Another 1,947 customers had their names, cities and email addresses compromised.
At the time, Trezor said the potential impact had been limited by a policy requiring fulfillment partners to delete or anonymize order information 90 days after delivery.

Trezor Hardware Wallets Remain Secure
Trezor stressed that its own systems were not compromised as part of the incident.
The company also said its hardware wallets remain secure, meaning the breach did not directly expose users’ crypto holdings or compromise the devices themselves.
However, leaked personal information can still create serious risks for hardware wallet owners.
Trezor warned affected customers to watch for phishing emails, fraudulent phone calls and physical letters that could attempt to impersonate the company or trick users into revealing sensitive information.
Address Leaks Create Additional Security Risks
The exposure of shipping addresses can be particularly concerning for hardware wallet customers because it may identify individuals who are likely to own cryptocurrency.
A similar incident involving Ledger in 2020 exposed information belonging to more than 270,000 customers.
Names, email addresses, phone numbers and, in some cases, home addresses were later published on a hacking forum.
Ledger customers continued reporting scam phone calls and physical letters years after the original breach, highlighting how stolen customer information can remain useful to attackers long after an incident occurs.
Trezor is now urging affected customers to remain cautious as the expanded ShipMonk breach increases the number of users potentially exposed to similar targeting.
Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.

6 hours ago
21








English (US) ·