Trezor said the data breach it disclosed last month was more severe than first reported, with another 67,000 U.S. customers now confirmed as affected.

The Prague, Czech Republic-based hardware wallet maker said Friday that the newly identified exposure included customers’ names, email addresses, phone numbers, shipping addresses and order numbers. According to Trezor, the leaked records came from orders placed between November 2019 and August 2021.
Trezor expands the scope of affected users
Trezor had first announced in August that data tied to 11,742 customers in the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal had been exposed. In that earlier disclosure, the company said the leaked information included names, email addresses, phone numbers and shipping addresses.
In its latest update, Trezor wrote: 「Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021…」
Trezor also said another 1,947 customers had their names, cities and email addresses exposed in the breach.
Trezor says ShipMonk failed to delete customer data
In Friday’s announcement, the company said its third-party fulfillment partner, ShipMonk, had falsely reassured Trezor that customer data had been deleted.
Trezor wrote: 「Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications.」 The company added: 「We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.」
Neither Trezor nor ShipMonk immediately responded to questions from Bitcoin Magazine.
Incident was first disclosed in August
When Trezor first revealed the breach in August, it said ShipMonk had experienced unauthorized access to systems containing customer data. The company also said it had directly emailed all customers involved in the incident.
Trezor’s parent company, SatoshiLabs, told Bitcoin Magazine last month that it was investigating the matter.
Hardware wallet users have faced similar incidents before
Trezor is one of the best-known Bitcoin hardware wallet providers and also supports storage for other cryptocurrencies.
The report noted that Bitcoin users’ personal data has been targeted before. In 2020, an unauthorized party accessed hardware wallet maker Ledger’s e-commerce and marketing database, exposing more than 1 million email addresses and the personal contact data of nearly 10,000 customers.
Earlier this year, customers also reported receiving emails from Global-e, Ledger’s payment partner, saying that a breach in its cloud systems had exposed sensitive customer data.
The story was first published by Bitcoin Magazine and written by Mathew Di Salvo.

