uMaHF0G5M1jYL9t88qHEEkQggU6GJ5wTZlhvItt7
Bookmark

Trezor Shipping Breach Expands, Exposing Data of 67,000 More U.S. Customers

Trezor says 67,000 more U.S. customers were exposed in the ShipMonk breach, raising concerns over phishing and crypto security risks.

Trezor said a data breach involving its shipping provider, ShipMonk, has expanded to affect another 67,000 U.S. customers, significantly increasing the known scope of an incident first disclosed last month.

The newly identified customers placed orders between November 2019 and August 2021. According to information shared by @coinbureau and Trezor’s latest disclosure, the exposed records included names, email addresses, phone numbers, shipping addresses and order numbers.

ShipMonk Retained Older Customer Records

The latest disclosure cryptocurrency centers on customer information that Trezor said should no longer have been held by its fulfillment provider. Trezor said it had repeatedly requested that ShipMonk delete the records and received written assurances that the information had been removed in accordance with contractual requirements and its data policy.

The company said it was disappointed markets to discover that the information remained in ShipMonk’s systems.

The incident had initially been disclosed in August, when Trezor said nearly 14,000 customers were affected. The original group included 11,742 customers whose names, email addresses, phone numbers and shipping addresses were exposed, along with another 1,947 customers whose names, cities and email addresses were disclosed.

The additional 67,000 records bring the known number of affected customers to roughly 80,000, according to reporting on the expanded breach.

Trezor Systems and Devices Were Not Compromised

Trezor emphasized that its own systems financial were not breached and that customer hardware wallets remain secure. The exposure concerns personal and order information held by the third-party shipping provider rather than wallet credentials or device security.

Nevertheless, the combination of names, phone numbers and physical addresses presents a significant social-engineering risk for cryptocurrency users. Attackers could use the information to make fraudulent emails, phone calls or physical correspondence appear more credible.

The development also highlights the security risks created by third-party data retention in the hardware-wallet industry. Trezor has warned affected customers to remain alert for impersonation attempts and other scams.

All newly affected customers were contacted by Trezor, while the company continues to address the wider implications of the ShipMonk incident. The key unresolved issue is how long customer records should remain accessible to fulfillment  markets  providers and how companies can independently verify that contractual deletion requirements are actually enforced.


Writer: Victoria Hale  
Technology & Blockchain Writer

Victoria Hale writes about blockchain technology, digital infrastructure, and the intersection of emerging technologies with finance. Her articles explore how new protocols and systems are shaping the evolving digital economy.

She prioritises clarity and accuracy when explaining technical developments to a general audience.

Check out other news and articles on Google News

Disclaimer:

The articles on HOKA.NEWS are here to keep you updated on the latest buzz in crypto, tech, and beyond—but they’re not financial advice. We’re sharing info, trends, and insights, not telling you to buy, sell, or invest. Always do your own homework before making any money moves.

HOKA.NEWS isn’t responsible for any losses, gains, or chaos that might happen if you act on what you read here. Investment decisions should come from your own research—and, ideally, guidance from a qualified financial advisor. Remember:  crypto and tech move fast, info changes in a blink, and while we aim for accuracy, we can’t promise it’s 100% complete or up-to-date.

Stay curious, stay safe, and enjoy the ride! hoka.news