67,000 More Trezor Customers Exposed as Data Breach Widens

Summary

A ShipMonk breach exposed another 67,000 Trezor customers’ names, emails, phone numbers, home addresses, and order numbers. All affected customers are in the U.S. and ordered between November 2019 and August 2021. Trezor said it had repeatedly been told the data was deleted under a 90-day retention policy, but later learned it was not. The total number of exposed customers now stands at about 80,700, up from 13,689. Trezor said its own systems were not breached and that private keys, devices, and wallet backups were not exposed. The main risk is physical targeting and phishing, since the records link hardware wallet ownership to home addresses. The breach traces to a critical SQL injection flaw in Metabase used by ShipMonk. Trezor is pushing anonymous delivery options such as locker pickup and neutral packaging.

Latest News!