Is it anywhere confirmed that only Coldcard buyers (or general Coinkite customers) received such targeted snail mail?
I would assume that there's some sort of leak simply because snail mail isn't for free and if you pay for your scam letters a scammer wants to do it as targeted as possible. It doesn't make sense to receive such a scam letter when you're no Coldcard customer.
And Coinkite not knowing if they lost customer data doesn't say much or worse opposite if they had bad opsec.
It could be as with Ledger (again) recently: not our fault, a contractor we chose leaked the data, not our problem. Dooh!

(What Ledger refuses to admit or communicate is that they are still responsible under EU GDPR for a failure of a sub-contractor. They can't wash their hands clean for the occured personal data loss at their sub-contractor. They can sue their sub-contractor but that doesn't solve the data loss and privacy issue. Who still buys Ledger crap anyway?)