Trezor’s data breach has widened sharply after its shipping partner ShipMonk discovered that thousands of older customer records remained on its systems. The hardware wallet maker said Friday that another 67,000 U.S. customers were affected, bringing the known total to about 80,689.
The newly exposed records relate to orders placed between November 2019 and August 2021. They include names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor said ShipMonk notified it of the additional records on Sept. 2.
Older Records Raise Data Retention Questions
The disclosure raises concerns about how ShipMonk handled customer data. Trezor said it repeatedly requested the deletion of older records and received written assurances that the information had been removed.
However, the company now says those records remained in ShipMonk’s systems. The discovery also challenges the effectiveness of Trezor’s 90-day data retention policy, which was initially cited as a key reason the August breach affected fewer customers.
The original disclosure involved 13,689 customers. Of those, 11,742 had names, email addresses, phone numbers, and shipping addresses exposed. Another 1,947 customers had more limited information exposed.
Wallets Remain Secure
Trezor said its own systems were not compromised. The breach also did not expose private keys or wallet backups, meaning attackers did not gain direct access to customers’ cryptocurrency through the incident.
However, the leaked information could create significant risks for affected customers. Attackers may use names, addresses, order details, and contact information to craft convincing phishing messages or impersonate Trezor and financial services.
Trezor has urged affected users to remain cautious about unexpected emails, calls, and letters. Customers should never provide wallet backups or enter recovery phrases into websites, regardless of who appears to request them.
The company said all newly identified customers have been contacted directly by email. The expanding breach highlights how third-party logistics providers can create security risks even when a cryptocurrency company’s core systems and wallets remain protected.