Hardware wallet maker Trezor said another approximately 67,000 U.S. customers were affected by a data breach at shipping provider ShipMonk, after initially reporting that nearly 14,000 customers had their personal information exposed.

Trezor said Friday that ShipMonk informed it on Sept. 2 that the breach was larger than previously disclosed and included order data from customers who placed orders between November 2019 and August 2021. The newly identified records contain customers' names, emails, phone numbers, shipping addresses, and order numbers.

The company said it had repeatedly asked ShipMonk to delete the data throughout their relationship and received written assurances that it had been removed in line with its contract, data policy, and previous communications. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems," Trezor said.

Trezor systems not compromised

Trezor said its own systems were not compromised and its hardware wallets remain secure. The company said it has emailed all customers affected by the latest disclosure. It warned them to watch out for scam emails, fraudulent calls, and letters, as well as potential physical security risks.