Trezor said Friday that a breach at shipping provider ShipMonk affected far more customers than it first disclosed, with another 67,000 U.S. buyers now added to the list of impacted users.

The hardware wallet maker said the newly identified records include names, email addresses, phone numbers, home addresses and order numbers tied to purchases made between November 2019 and August 2021. The update raises the total number of affected customers to roughly 80,700, up from 13,689 disclosed in August.

Scope of the newly identified exposure

According to Trezor, all of the additional customers are based in the United States. The company said ShipMonk informed it of the expanded impact two days before Friday's announcement.

The exposed records relate to orders placed from November 2019 through August 2021. Based on that timeframe, some of the data involved is now several years old, with the oldest records dating back to nearly seven years ago.

What data was involved

Trezor said the newly exposed information consists of customer names, email addresses, phone numbers, home addresses and order numbers. The company did not indicate in the statement that payment data or wallet contents were part of this newly disclosed set.

The latest disclosure substantially widens the known scale of the ShipMonk incident. Trezor's August notice had put the impact at 13,689 customers, but the revised figure now stands at about 80,700 in total.

Deletion assurances now in question

Trezor said it had repeatedly requested and received written confirmation that these customer records had been deleted. The company said those assurances were meant to reflect its contract terms and internal data policy.

That matters because, when Trezor first disclosed the breach in August, it said the incident appeared limited in scope partly due to a 90-day deletion policy negotiated into its fulfillment partners' terms. The discovery of tens of thousands of older records at ShipMonk undermines that earlier understanding.

What is confirmed so far

At this stage, Trezor's update confirms a larger set of exposed customer information tied to one shipping provider and a defined ordering period. The company has not, in the source report, announced a different timeline for the breach itself or disclosed further categories of affected users beyond the newly identified U.S. customers.

The immediate next confirmed development is ShipMonk's updated finding, which Trezor says it received two days earlier. The revised customer count and the apparent failure to delete old records are now central to the fallout from the incident.

Source: decrypt.co