← Blog · · df00tech

Trezor Discloses Additional 67,000 U.S. Customers Affected by ShipMonk Breach

security-news breach

Hardware wallet maker Trezor disclosed on Friday that a breach at its third-party shipping provider, ShipMonk, exposed data belonging to an additional 67,000 U.S. customers. The exposed information includes names, email addresses, phone numbers, shipping addresses, and order numbers tied to orders placed between November 2019 and August 2021. Notably, Trezor says this data had previously been reported as deleted. According to the disclosure, the breach does not affect the security of Trezor's hardware wallets themselves.

Why It Matters

This is a supply-chain / third-party vendor exposure rather than a direct compromise of Trezor's own systems or products. For a cryptocurrency hardware wallet vendor, however, even non-financial PII (names, addresses, phone numbers, order history) is high-value to attackers because it can be used to identify likely crypto asset holders and craft highly targeted phishing, SIM-swapping, or physical-threat ("wrench attack") campaigns against affected customers. The fact that data thought to be deleted resurfaced also raises questions about vendor data retention and deletion assurances more broadly — a concern relevant to any organization relying on third-party fulfillment or logistics providers that handle customer PII.

What Defenders Should Watch For

  • If your organization uses ShipMonk or similar third-party fulfillment/shipping providers, review data retention and deletion attestations — this incident suggests "confirmed deleted" claims from vendors may need independent verification.
  • Affected individuals (or organizations with customers in similar hardware wallet / high-value-asset niches) should be alert to targeted phishing referencing past orders, fake "security update" or "wallet migration" lures, and social-engineering attempts using real name/address/order details for legitimacy.
  • Security teams supporting crypto-adjacent customer bases should consider proactive customer communications and monitoring for phishing campaigns that reference legitimate historical order data, since such details lend false credibility to lures.
  • Review your own vendor risk management: which third parties hold historical customer PII, what their actual deletion practices are, and whether contractual deletion commitments are periodically verified rather than assumed.

This is a developing story based on Trezor's own disclosure, and details may be updated as more information becomes available. For the full report, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.