Summary
- Another 67,000 US customers have been added to the known impact, taking the total to roughly 81,000.
- The newly disclosed records cover orders from November 2019 to August 2021.
- Trezor says ShipMonk had repeatedly provided written assurances that the historical data had been deleted.
The customer impact of a breach at Trezor’s logistics provider has expanded to roughly 81,000 people after historical order records the hardware-wallet company believed had been deleted were found to have remained in the supplier’s systems.
Trezor says another 67,000 customers in the United States are affected by the breach at ShipMonk. The newly identified records relate to orders placed between November 2019 and August 2021 and include names, email addresses, telephone numbers, shipping addresses, and order numbers.
The additional group substantially expands an incident first disclosed in August, when Trezor said 13,689 customers had been affected. The earlier exposure included customers in the UK, Italy, Portugal, Sweden, Brazil, Colombia, and the US.
The latest disclosure also changes the governance dimension of the breach. Trezor says the newly identified historical information should no longer have existed in ShipMonk’s systems.
The company says it repeatedly requested and received written assurances that the data had been deleted in accordance with its contract, data policy, and previous communications with the logistics provider. It later discovered that the records were still retained.
That creates two separate failures to examine. The compromise at ShipMonk determined how an attacker gained access to customer information, while the retention of historical data determined how much information was available to be exposed once the supplier was breached.
Trezor says its own systems were not compromised and that customers’ hardware wallets remain secure. The disclosed data does not include recovery seeds or private keys.
The information that was exposed can nevertheless support highly targeted impersonation. Hardware-wallet owners represent an unusually valuable population for criminals because knowledge of a person’s purchase can make fraudulent emails, telephone calls, letters, or other approaches considerably more convincing.
Shipping addresses create a further concern. The data connects an identifiable individual and physical address with the purchase of a cryptocurrency security product, a combination Trezor itself has warned can create physical as well as digital security risks.
The incident also demonstrates the limits of relying on contractual deletion requirements without effective verification. Organisations routinely require suppliers to remove customer information after a retention period, but a contractual obligation does not itself cause the data to disappear from operational databases, backups, archives, or other systems.
Where a supplier continues to hold records beyond the intended period, the organisation that originally collected the data retains an exposure it may believe has already been removed.
European data-protection principles require personal information to be kept no longer than necessary for the purpose for which it was collected. Outsourcing fulfilment does not eliminate the need to understand what information remains with a logistics provider and whether deletion requirements are actually being carried out.
The original ShipMonk incident had already demonstrated the consequences of placing customer information in a third-party supply chain. The newly disclosed historical records add a different control failure: information that Trezor says should have been removed remained within reach when the supplier was compromised.
Trezor has contacted affected customers directly and warned them to be alert for fraudulent emails, calls, letters, and other forms of impersonation.
The known breach population has therefore grown several times over without a new intrusion. The expansion comes from discovering that the breached supplier retained far more historical customer information than Trezor understood it still possessed.





