Trezor says the impact of an August data breach at its shipping and logistics provider ShipMonk has widened to 81,000 customers, according to BleepingComputer. The hardware wallet maker had previously disclosed on August 13 that attackers accessed data for nearly 14,000 customers; its latest update adds another 67,000 U.S. customers. The newly identified group covers U.S. customers who ordered between November 2019 and August 2021, BleepingComputer reports, citing Trezor. The exposed fields for those customers included names, email addresses, phone numbers, shipping addresses, and order numbers. The earlier disclosure covered full names, shipping addresses, email addresses, and phone numbers. Trezor’s initial disclosure also included customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026, according to BleepingComputer. The company’s Friday update said the additional exposure occurred after ShipMonk did not delete data from its systems as Trezor says was required under its contract and data policy. Trezor says the breach did not affect its operations or services, that its own systems were not compromised, and that Trezor devices remain secure. That distinction matters: the reported incident concerns customer contact and order data held by a logistics provider, not wallet firmware, private keys, or device security. The risk is still material for customers. Trezor warned affected users that the leaked information could be used in phishing emails, fraudulent calls, letters, or other scams. Because the data includes shipping addresses and phone numbers, Trezor also flagged potential physical-security risk for affected individuals. BleepingComputer reports that Trezor has not publicly detailed how ShipMonk’s systems were breached. However, breach notification emails seen by the outlet said attackers exploited a vulnerability in Metabase, a third-party analytics platform. BleepingComputer also links the incident to a broader Metabase campaign in which threat actors exploited a critical SQL injection zero-day to access customer instances and steal data. The outlet further reports that ShipMonk has received extortion emails from the ShinyHunters extortion gang. BleepingComputer says other companies affected in the Metabase campaign include online form-building platform Tally and laptop maker Framework, both of which have notified customers about breaches after their instances were hijacked. This is not Trezor’s first customer-data incident. In January 2024, the company disclosed a separate breach involving a third-party support ticketing portal that exposed data for roughly 66,000 users, including names, usernames, and email addresses, according to BleepingComputer. The outlet says that stolen data was later used in phishing attempts seeking victims’ 24-word wallet recovery seeds. Who benefits: There is no clear commercial beneficiary from the breach. Attackers and fraud operators may benefit if the exposed data helps them target Trezor customers with more convincing scams. Who's exposed: Affected Trezor customers are exposed to phishing, fraudulent calls or letters, and potentially physical-security risks, according to the company’s warning reported by BleepingComputer. ShipMonk is also exposed to scrutiny over data retention practices described by Trezor.