Hardware wallet maker Trezor has revealed that a data breach initially disclosed last month is significantly larger than first estimated.
Based in Prague, Czech Republic, the company stated on Friday that an extra 67,000 U.S. customers experienced leaks of their names, emails, phone numbers, order numbers, and shipping addresses. Trezor noted that this compromised information stems from purchases placed between November 2019 and August 2021.
Initially, Trezor reported in August that data belonging to 11,742 customers across the UK, U.S., Colombia, Sweden, Brazil, Portugal, and Italy had been compromised, exposing names, email addresses, phone numbers, and shipping locations.
Additionally, 1,947 customers had their names, cities, and email addresses exposed during the security incident.
In its Friday statement, Trezor explained that ShipMonk, its third-party fulfillment vendor, had provided false assurances regarding the deletion of customer records.
“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” Trezor stated.
“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”
Neither ShipMonk nor Trezor responded immediately to inquiries from Bitcoin Magazine.
When the breach was first announced in August, Trezor stated the leak occurred because ShipMonk suffered “unauthorized access to their systems containing customer data.”
The manufacturer also mentioned that it had sent direct emails to every customer impacted by the breach. SatoshiLabs, the parent company of Trezor, informed Bitcoin Magazine last month that an investigation into the event was underway.
As a leading provider of Bitcoin hardware wallets, Trezor also offers storage support for various other digital assets.
Personal data belonging to Bitcoin users has previously been targeted by hackers. In 2020, an unauthorized entity breached the marketing and e-commerce database of rival hardware manufacturer Ledger, exposing more than 1 million email addresses alongside personal contact details for nearly 10,000 buyers.
Early this year, users reported receiving notifications from Ledger payment partner Global-e indicating that a cloud system breach had exposed sensitive customer details.
Frequently Asked Questions
How many additional U.S. customers were exposed in the Trezor breach?
An additional 67,000 U.S. customers had their data exposed, according to Trezor’s update.
Which company was responsible for the third-party fulfillment?
ShipMonk served as Trezor’s third-party fulfillment partner.
What specific information was leaked?
Names, emails, phone numbers, shipping addresses, and order numbers were among the leaked details.
When did the affected purchases take place?
The impacted orders occurred between November 2019 and August 2021.


