Skip to content
Tech News
← Back to articles

Trezor data breach impact now reaches 81,000 customers

read original get Trezor Safe 5 Hardware Wallet → more articles
Why This Matters

A breach at Trezor's third-party logistics provider ShipMonk has ballooned from 14,000 to 81,000 affected customers, after ShipMonk allegedly retained data it had contractually promised to delete — including orders dating back to 2019. Because the exposed data includes names, phone numbers and home addresses of known crypto hardware wallet buyers, it creates unusually high phishing and physical-safety risk. It's a sharp reminder that vendor data-retention promises are only as good as their verification.

Key Takeaways
Worth a Look

Trezor Safe 5 Hardware Wallet — If the news has you thinking about how your crypto keys are stored, the Trezor Safe 5 keeps private keys offline on a dedicated device with a color touchscreen and PIN protection. It supports a wide range of coins through Trezor Suite, so you can move funds off exchanges and hold them yourself. A shipping-vendor leak of contact data is a good reminder to lock down the assets themselves.

See Trezor Safe 5 Hardware Wallet on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers.

In total, the breach has affected 81,000 customers after Trezor initially disclosed on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers.

As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026.

On Friday, it published an update to confirm that the breach impact has expanded after ShipMonk failed to delete the exposed data from its systems as required by Trezor's contract and data policy.

"Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed," Trezor said.

"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."

The company added that the breach did not affect its operations or services, that its systems were not compromised, and that all Trezor devices are secure.

It also warned affected customers to be wary of any messages requesting personal information, as they may be targeted in phishing attacks.

"Be aware of the increased risk of phishing. The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks," Trezor said.

Metabase campaign linked to ShinyHunters extortion gang

... continue reading