Hardware wallet maker Trezor said the scale of a data breach involving logistics partner ShipMonk was underestimated, with information from about 67,000 additional U.S. users fully exposed. The affected orders were placed between November 2019 and August 2021.
According to Foresight News, the leaked data included names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor said it had repeatedly confirmed with ShipMonk that the data had been deleted under contract and data policy and had received written assurances, but the information was not actually removed from ShipMonk's systems.
Trezor said its own systems were not affected and that its hardware wallets remain secure, though impacted users may face a higher risk of targeted phishing attacks. All affected users have been notified individually by email.
The incident was first disclosed on August 13, when about 13,700 users were said to be affected. Trezor said it is accelerating the rollout of an anonymous shipping service to reduce information exposure when users place orders.