Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000 additional US customers. This significantly broadens the scope of an incident initially reported in August.
The newly identified data pertains to Trezor orders processed during a prior partnership with ShipMonk, which lasted from November 2019 to August 2021. ShipMonk notified Trezor on September 2 that the breach included this older historical order data.
The exposed records consist of customers’ full names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor has directly informed the affected individuals via email.
Customers who have not received a notification from the company’s official email address ([email protected]) are not believed to be impacted by this expansion of the breach.
ShipMonk Data Breach
Trezor indicated that it had repeatedly received written assurances from ShipMonk that customer data from their previous business relationship had been deleted.
These assurances were reportedly provided in accordance with contractual obligations, Trezor’s data retention policies, and previous communications between the two companies.
The company expressed disappointment at discovering that the records had remained in ShipMonk’s systems despite these earlier assurances.
This situation raises concerns about third-party data lifecycle management, particularly regarding whether service providers can ensure that archived, backup, and operational data has been securely removed after a customer relationship ends.
The 67,000 newly disclosed records are distinct from the initial breach notification published on August 13, which reported unauthorized access to ShipMonk’s systems affecting 11,742 Trezor customers, resulting in the full exposure of their names, phone numbers, email addresses, and shipping addresses.
An additional 1,947 customers experienced partial exposure, which included their names, cities, and email addresses.
Trezor emphasized that its own systems were not compromised and that the hardware wallet devices remain secure. However, the stolen personal information could enable highly convincing social-engineering campaigns.
Threat actors might use order details and shipping addresses to impersonate Trezor support, cryptocurrency exchanges, banks, or delivery companies.
Potential attacks can include phishing emails, fraudulent support calls, SMS messages, mailed letters, and fake recovery procedures designed to steal cryptocurrency wallet backup phrases.
Moreover, the breach poses potential physical security concerns, as the exposed records link identifiable individuals to hardware wallet purchases and residential delivery addresses. Criminals could utilize this information to profile potential cryptocurrency holders or target them for extortion and theft.
Trezor urged customers to treat unsolicited communications that request urgent action or personal information as suspicious. Users should verify messages through official Trezor channels and never disclose wallet backups, recovery seeds, or private keys to any website, support representative, or third party.
The company also recommended privacy-conscious purchasing measures, including using separate email addresses, making cryptocurrency payments when possible, utilizing disposable virtual cards, and choosing P.O. Box delivery options.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

