Hardware wallet maker Trezor has confirmed that a data incident at its fulfillment partner ShipMonk reached far more people than first announced. In a September 4, 2026 update to its official notice, the company said ShipMonk contacted it on September 2 with word that stolen files also contained order records from an earlier working relationship that ran from November 2019 through August 2021.
Those older files affect about 67,000 additional customers in the United States.
Added to the roughly 13,689 people named in the mid-August disclosure, the identified total now approaches 80,700.
Trezor said every newly identified buyer has been emailed from its security address.
Anyone who did not receive that message is not part of the expanded group.
The extra records include full name, email address, telephone number, shipping address, and order number.
Trezor repeated that its own infrastructure was not entered, and that devices, private keys, recovery phrases, and wallet backups were never part of the stolen set.
What leaked is the information a warehouse needs to print a label and hand a box to a courier. That combination still matters.
It marks a person as a confirmed owner of a hardware wallet and ties that person to a street address, which can make phishing emails, fake support calls, and mailed scams more convincing.
Trezor also flagged a possible increase in physical security risk and urged customers to treat unexpected contact that cites an old order as hostile until proven otherwise.
When the company first published the story on August 13, it described a narrower event.
ShipMonk had reported unauthorized access on August 10. Trezor then listed 11,742 customers with full exposure of name, email, phone, and shipping address, plus 1,947 with partial exposure limited to name, city, and email.
Those recent shipments went out between May 10 and August 8, 2026, to addresses in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
At that time Trezor credited a strict 90-day data-retention rule that it said it had written into contracts with fulfillment partners.
Older files, the company believed, had already been deleted or anonymized.
The September update shows that belief was wrong for the 2019–2021 US cohort.
Trezor stated that throughout the relationship it had asked for deletion and had received written confirmation that the data was gone, in line with the contract, its own data policy, and earlier messages.
It said it was disappointed that those confirmations did not match what remained on ShipMonk’s systems.
The mismatch matters because hardware-wallet buyers are a high-value target.
Attackers who know that a specific household purchased a Trezor years ago can craft messages that look like official support, a customs notice, or a warranty follow-up.
Trezor told customers never to type a recovery phrase into a website, never to read it over the phone, and never to assume that a caller who already knows an old order number is legitimate.
Official communication, the company said, comes from known addresses and does not demand seed words.
Parcel contents themselves were not in the leaked files.
The episode is a reminder that even firms built around offline key storage still depend on third parties that keep names and doorstep details.
Trezor called the incident the first since its 2013 founding in which customer phone numbers and shipping addresses were exposed.
In response it has pointed to anonymous-delivery options rolling out in the European Union and planned for the United States later in the year, so that future shipments need not carry a home address in the same way.
Those measures do not erase the older records that should have been purged.
Customers who received a notice should stay alert for weeks or months, not days.
Scam campaigns often lag a public disclosure.
Checking that a Trezor device still boots and that firmware is current is useful hygiene, but it does not address the leaked mailing data.
Changing email passwords, enabling strong authentication on accounts tied to that address, and being cautious about unexpected packages or visitors are practical steps.
People who never got an email from Trezor’s security team can treat themselves as outside the newly disclosed US group, though the original August cohort remains separately notified.
Third-party risk of this kind is difficult to eliminate.
Written deletion clauses and audit letters only work if the partner actually removes the files.
Trezor’s update makes that gap public and asks affected buyers to assume that names, phones, and addresses from 2019–2021 may now circulate among criminals. The wallets themselves, the company insists, were not compromised. The personal data that was supposed to vanish years ago was.