Trezor breach expands to 81,000 customers after logistics partner's data retention failure

Trezor, a cryptocurrency hardware wallet maker, updated its breach disclosure to include an additional 67,000 U.S. customers, bringing the total affected to 81,000. The incident originated at its shipping provider ShipMonk, which failed to delete customer data as contractually required. Trezor advises affected customers to be wary of phishing attempts and fraudulent communications.
The initial disclosure covered roughly 14,000 customers across several countries, but the updated figure adds 67,000 U.S. buyers who placed orders between November 2019 and August 2021. The root cause is ShipMonk's failure to purge customer records despite contractual obligations and repeated written assurances of deletion.
The attackers exploited a critical SQL injection zero-day in the Metabase analytics platform, with the ShinyHunters extortion gang sending demands to ShipMonk. This mirrors a 2024 Trezor incident where stolen support-ticket data fueled phishing attempts to steal wallet recovery seeds.
The expanded breach could heighten risks for affected cryptocurrency holders, as leaked shipping addresses and contact details may enable sophisticated phishing campaigns or even physical targeting. Since Trezor devices remain secure, the primary threat is social engineering aimed at extracting recovery seeds. This incident may also underscore broader supply-chain vulnerabilities, where third-party data retention practices undermine customer privacy protections across the tech sector.