What's interesting, considering the period covered by the stolen data, is that it likely means the breach had already occurred by April or, at the latest, early May but you chose to keep it silent until recently, around the same time Trezor announced its own data breach.
What's even more concerning is that some of your users were already receiving phishing attempts while some already getting compromised yet you chose not to be transparent, warn users, or create awareness.
Instead, you denied it.
Putting their personal data at risk and still lying to them
Just crazy