Trezor says ShipMonk exposed 67,000 more US buyers from 2019–2021 despite deletion assurances, widening the breach to about 80,700 customers.