Trezor disclosed that a data breach at its shipping provider compromised personal information for 67,000 additional US customers, expanding the scope of an incident that poses concrete risks to hardware wallet users.

The breach exposed names, email addresses, phone numbers, and shipping addresses for the affected customers. Trezor stated that financial information and private keys remained secure, but the leaked data creates a direct attack surface for bad actors. Scammers now possess verified contact details for hardware wallet owners, enabling targeted phishing campaigns and social engineering attempts designed to trick users into revealing sensitive information or transferring assets.

This is the second disclosed batch of affected customers from the same shipping provider incident. The staggered disclosure pattern raises questions about Trezor's breach notification timeline and whether additional waves of compromised user data remain undisclosed.

Hardware wallet manufacturers occupy a unique position in the security landscape. Trezor users represent high-value targets because they actively manage cryptocurrency holdings. Attackers know these customers possess digital assets worth protecting. With verified contact information in hand, scammers can craft convincing messages impersonating Trezor support, claiming account compromises or suspicious activity, and requesting verification through fake login portals. The phishing risk escalates because victims already expect communications from the company.

Shipping address data compounds the threat. Criminals could use this information for physical attacks, including theft of replacement devices or interception of legitimate support packages. They might also deploy SIM swapping attacks using the phone numbers to hijack customer accounts on centralized exchanges or email providers.

Trezor recommended affected customers monitor their email accounts and phone numbers for suspicious activity. The company advised users to ignore unsolicited communications claiming to be from Trezor and to verify any support requests through official channels. These are baseline precautions that shift responsibility to users already victimized by the breach.

The incident reflects broader supply chain vulnerabilities in the hardware wallet industry. Trezor relies on third-party logistics providers to deliver physical devices to customers. A single compromised shipping partner can expose hundreds of thousands of users simultaneously. Other hardware wallet manufacturers face identical risks through their own supply chains.

This breach arrives amid ongoing scrutiny of Trezor's security practices. The company has faced criticism over past vulnerabilities and disclosure practices. Each new incident erodes user confidence in the brand's ability to protect customer data.

The crypto community expects hardware wallet providers to maintain fortress-level security standards. When breaches occur at support companies or logistics partners, customers view these as preventable failures. Users expect manufacturers to implement robust due diligence, vendor security requirements, and breach detection systems.

Trezor users should activate two-factor authentication on all associated email accounts and enable account recovery options that don't rely on phone number verification alone. Monitoring credit bureaus for fraudulent activity and considering identity theft protection services makes sense for affected customers. Existing cryptocurrency holdings on affected Trezor devices face no immediate risk if users maintain proper operational security, but the leaked personal data creates persistent social engineering threats lasting months or years.

The 67,000 figure represents a significant portion of Trezor's US user base, suggesting the shipping provider handled substantial volumes of hardware wallet shipments. Future hardware wallet purchases may trigger similar risks unless manufacturers overhaul vendor security practices across their entire logistics ecosystem.