Trezor has revised its disclosure about the data breach tied to logistics partner ShipMonk, saying the incident was far bigger than first reported. This time, the hardware wallet company said another 67,000 US customers who made orders from November 2019 through August 2021 had their personal data fully exposed: names, email addresses, phone numbers, shipping addresses, and order numbers.
Breach Scale Expanded
Trezor said it had repeatedly checked with ShipMonk and was told the relevant data had been deleted in line with contract terms and data policies. It also said it received those assurances in writing. But the data was never actually deleted from ShipMonk's systems. The first disclosure, published on August 13, said about 13,700 users were affected.
Security Update and Phishing Risk
Trezor said its own systems were not affected and that its hardware wallets are still secure. Even so, affected users could face a higher risk of targeted phishing attacks. Short and ugly. The company said every impacted customer has been notified individually by email.
Anonymous Shipping Service Accelerated
In response, Trezor said it is speeding up the rollout of an anonymous shipping service meant to reduce how much personal information is exposed during the ordering process.

