Trezor has disclosed that a data breach at its shipping provider ShipMonk has expanded to expose the personal information of an additional 67,000 customers, marking a significant escalation in the scope of a previously reported incident. The hardware wallet manufacturer confirmed that newly identified records date from 2019 to 2021 and include sensitive personal details such as names, email addresses, phone numbers, shipping addresses, and order numbers, as reported by The Block.

The expanded breach raises serious questions about data retention practices at ShipMonk. According to Decrypt, some records exposed in the breach date to 2019, representing a period years beyond the 90-day retention policy Trezor said its partners had agreed to. This discrepancy suggests the shipping provider retained customer data significantly longer than contracted, potentially violating data handling agreements and industry standards for data minimization.

The incident specifically affects United States-based users, opening avenues for targeted cyberattacks that could compromise wallet security through indirect means. Cointelegraph reported that the exposure creates risks for potential phishing attacks and social engineering scams. While hardware wallets themselves remain secure—the breach did not compromise private keys, seed phrases, or cryptocurrency holdings—the exposed personally identifiable information enables attackers to craft highly convincing fraudulent communications tailored to specific victims.

Threat actors could leverage the leaked names, physical addresses, email addresses, and phone numbers to impersonate Trezor support staff or create fake shipping notifications designed to trick users into revealing wallet credentials, seed phrases, or downloading malicious software that could drain wallets. The temporal scope of the data, spanning multiple years from 2019 through 2021, increases the risk profile as it provides attackers with historical context about customer relationships and purchasing patterns with the company.

This disclosure represents a substantial expansion of a previously reported data incident at ShipMonk. The widening scope suggests initial assessments of the breach's impact were incomplete, requiring Trezor to issue updated notifications to affected customers years after the original data collection occurred and potentially after customers assumed their data had been purged according to stated retention policies.

The incident highlights ongoing supply chain vulnerabilities in the cryptocurrency hardware sector, where third-party logistics providers handle sensitive customer information despite not being direct custodians of digital assets. The retention of customer data years beyond contracted limits raises compliance concerns regarding data protection regulations that mandate specific retention schedules and deletion protocols. As regulatory frameworks surrounding data privacy continue to evolve, discrepancies between agreed retention periods and actual storage practices may expose companies to additional legal and financial liabilities beyond the immediate security risks of the exposed information.