Trezor says data breach affects another 67K US customers
Source Entity
Cointelegraph by Zoltan Vardai

Trezor has disclosed that a shipping partner's data breach has impacted an additional 67,000 US customers. The exposed data, including contact information and order history, poses significant risks for phishing and social engineering attacks.
Trezor Data Breach Expansion: A Critical Security Update
Hardware wallet manufacturer Trezor has confirmed that a previously identified data breach involving its third-party shipping provider, ShipMonk, is significantly larger than initial estimates suggested. The company announced that an additional 67,000 US customers have been affected, marking a major escalation in the scope of the incident. This development underscores the persistent vulnerabilities inherent in supply chain dependencies, where even a secure primary system can be compromised through the lapses of a peripheral service provider.
The Anatomy of the Exposure
According to Trezor, the impacted customer base primarily consists of individuals who placed orders between November 2019 and August 2021. The sensitive data exposed includes full names, email addresses, phone numbers, shipping addresses, and specific order details. Because this information is highly granular, it provides malicious actors with the exact context required to craft sophisticated, highly targeted phishing campaigns that could potentially deceive even security-conscious cryptocurrency holders.
Accountability and Third-Party Risks
Central to this incident is the failure of the shipping provider, ShipMonk, to adhere to data retention protocols. Trezor explicitly stated that they had received written assurances from ShipMonk that the data in question had been deleted. The failure to honor these commitments highlights a critical flaw in vendor management and data governance. When companies outsource logistics, the responsibility for data security remains a shared burden, yet the end-user often suffers the consequences when a partner fails to implement basic data hygiene practices.
Implications for Cryptocurrency Security
While Trezor confirmed that their internal systems and core infrastructure remained uncompromised, the exposure of physical shipping addresses and purchase history is particularly dangerous for the crypto community. Hardware wallets are designed to protect private keys, but physical security and privacy are essential components of that protection. If a user is known to own a hardware wallet, they become a prime target for social engineering, physical threats, or highly personalized 'SIM-swapping' attempts aimed at gaining access to their broader digital life.
Future Trends and Mitigation
Moving forward, this incident serves as a stark reminder that the 'security' of a cold storage device is only as strong as the ecosystem surrounding it. Users must remain vigilant, treating any communication regarding their Trezor device with extreme skepticism. As digital asset adoption grows, companies will likely face increased pressure to perform rigorous, continuous audits of third-party vendors. For the broader industry, the trend is shifting toward decentralized shipping logistics and minimized data retention to prevent such large-scale leaks from recurring.
Concluding Outlook
In summary, the breach of 67,000 additional US customers is a significant setback for data privacy in the hardware wallet sector. While the hardware itself remains secure, the exposure of PII (Personally Identifiable Information) creates a long-term risk profile for those affected. Users should expect an increase in targeted phishing attempts and should prioritize enabling multi-factor authentication (MFA) on all related accounts, remaining wary of any unsolicited correspondence claiming to be from Trezor or associated shipping entities.