Trezor says shipping-provider breach exposed data on 67,000 additional U.S. customers

BRIEF
Trezor said approximately 67,000 additional U.S. customers were affected by a breach at its shipping provider, ShipMonk. The exposed information covered customer names, email addresses, phone numbers, shipping addresses, and order numbers from November 2019 through August 2021. Trezor said the incident does not affect the security of its hardware wallets. Its disclosure also identified heightened phishing and physical-security risk associated with the exposed customer information. The supplied facts describe the data categories and the approximate number of additional U.S. customers, but do not establish whether every listed data field was exposed for every person, how the breach occurred, or whether any customer was defrauded. The incident highlights the security consequences of retaining customer information at a logistics provider, even when the underlying product is designed to protect digital assets. Organizations using shipping, fulfillment, or other service providers should verify data-retention and deletion claims, understand what information remains accessible, and prepare clear customer guidance for possible impersonation attempts. Customers should be cautious about unexpected communications that use delivery or order details to request action.
WHY IT MATTERS
A shipping record can provide enough context for a convincing impersonation attempt, even when the protected product itself was not compromised. The supplied disclosure specifically points to phishing and physical-security concerns, making this relevant to both cyber defense and personal safety. It also raises a practical third-party-risk question: organizations need evidence that sensitive customer information is deleted when promised, rather than relying only on contractual language. The facts do not confirm phishing, fraud, or physical attacks resulting from this incident.