A logistics database that had sat untouched for three years has now implicated 67,000 more users. Trezor has confirmed that following further investigation into the previously disclosed ShipMonk security incident, an additional 67,000 affected records have been identified, spanning from 2019 to 2021.

The newly confirmed data includes names, email addresses, phone numbers, shipping addresses, and order numbers. ShipMonk is the third-party logistics provider Trezor uses to handle order fulfillment — meaning what was leaked isn't private keys or wallet contents, but rather the shipping and contact information left behind when purchasing a hardware wallet.

For Trezor device owners, the most immediate risk from this combination of data is that it can be used to impersonate official customer support or shipping notifications for targeted phishing attacks — after all, attackers now have real order numbers and shipping addresses to back up their claims. Trezor has yet to publicly clarify whether affected users have been contacted or what further protective measures are being provided.