Trezor Reveals Additional 67,000 US Customers Exposed

A data breach at Trezor's logistics partner ShipMonk has exposed the personal information of an additional 67,000 US customers, nearly tripling the initial impact.

By Central
Trezor announced that ShipMonk retained customer data for years, exposing 67,000 more US customers to phishing and physical security risks.
Highlights
  • The breach at ShipMonk exposed personal data of 67,000 additional US customers, nearly tripling the initial count.
  • ShipMonk retained customer data for years beyond contractual deletion requirements, contradicting prior assurances.
  • The exposed data includes names, addresses, and order numbers, creating a dangerous phishing threat for hardware wallet owners.

Trezor’s disclosure that a data breach at its logistics partner ShipMonk exposed the personal information of an additional 67,000 customers in the United States has sharply escalated what initially appeared to be a contained incident, raising serious questions about third-party data-retention practices and the long-term security risks facing cryptocurrency hardware wallet users. The newly identified records, which Trezor announced on September 4, 2026, nearly triple the previously reported impact and reveal that ShipMonk had retained customer data for years beyond the contractual deletion requirements — a failure that now exposes a far larger pool of individuals to phishing, physical surveillance, and targeted social engineering attacks.

ShipMonk Breach Expands to Include Order Data Dating Back to 2019

The hardware wallet manufacturer, a subsidiary of SatoshiLabs, first disclosed the incident on August 13, 2026, after ShipMonk reported unauthorized access to systems containing Trezor order information. At that time, Trezor said 13,689 customers across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal were affected, with the bulk of exposures limited to orders placed between May 10 and August 8, 2026. That initial assessment assumed that ShipMonk had complied with a contractual requirement to delete or anonymize customer information after 90 days, a standard safeguard intended to minimize the blast radius of any future compromise.

A Delayed Discovery of Retained Historical Data

On September 2, ShipMonk notified Trezor that the breach was far more extensive. An additional 67,000 US customers who ordered Trezor products between November 2019 and August 2021 had their names, email addresses, phone numbers, shipping addresses, and order numbers exposed. Trezor stated that it had repeatedly received written assurances from ShipMonk during their partnership that older customer data had been deleted in accordance with contractual terms and the company’s own data retention policy. The retention of this historical data — spanning nearly two years of orders from more than half a decade ago — contradicts those assurances and suggests either a systemic failure within ShipMonk’s data governance or a deliberate choice to keep records for reasons that remain unclear.

What Information Was Exposed in the Trezor-ShipMonk Breach?

For the newly identified 67,000 US customers, the exposed data includes names, email addresses, phone numbers, shipping addresses, and order numbers. This is the same category of personal identifiable information (PII) that was compromised in the initial 13,689-customer incident. No wallet backups, private keys, recovery seeds, or device-level data were accessed, as Trezor’s own infrastructure and hardware wallets were not affected. However, the combination of cryptocurrency-related purchase history with full contact details creates a uniquely dangerous threat profile, because attackers can now create sophisticated, personalized phishing campaigns aimed at individuals who are known to own hardware wallets.

The Phishing and Physical Security Risk: Why Exposure Matters Beyond the PII

Cryptocurrency hardware wallets, like those produced by Trezor, are designed to store private keys offline, making remote theft of funds extremely difficult unless the attacker can trick the user into revealing their recovery seed or approving a malicious transaction. The ShipMonk breach does not provide any direct access to wallet funds, but it arms cybercriminals with precisely the kind of context that makes social engineering effective. Attackers who know a target’s name, address, phone number, and email — and who know that the target owns a Trezor device — can impersonate Trezor support, wallet developers, or even law enforcement with a high degree of credibility.

Concrete Attack Scenarios in the Wake of the Breach

A user who receives a call from someone claiming to be a Trezor security agent, referencing their recent order history and shipping address, may be far more likely to comply with a request to visit a fraudulent website or disclose their recovery seed. Similarly, physical letters or packages containing fake hardware replacements could be mailed to exposed addresses, instructing recipients to plug in the device or visit a phishing URL. Because the exposed data spans orders from as far back as 2019, some customers may no longer own the same phone number — but attackers can still cross‑reference shipped addresses, emails, and names to build detailed profiles. The long tail of this breach means that individuals who purchased a Trezor half a decade ago remain at heightened risk for years to come.

Supply Chain Data Governance: A Recurring Failure in the Crypto Industry

The Trezor incident is not the first time a cryptocurrency company has been let down by a third‑party logistics provider, but the scale and duration of unauthorized data retention make this case particularly egregious. Trezor had negotiated contractual data deletion timelines of 90 days, a standard clause in data processing agreements that is intended to limit exposure. ShipMonk’s failure to comply — over a five‑year period — indicates either a lack of automated deletion processes, inadequate auditing by ShipMonk, or a deliberate policy of retaining historical data for analytics or operational purposes. Trezor’s statement that it “repeatedly received written assurances” underscores a broader industry problem: contractual obligations around data deletion are notoriously difficult to enforce, and few companies have the resources or leverage to conduct regular, independent audits of their vendors’ databases.

Implications for the Hardware Wallet Market and User Trust

For Trezor, which has cultivated a reputation for security‑first design, the ShipMonk incident could erode user trust, particularly among privacy‑conscious cryptocurrency users. While the company’s own products remain uncompromised, the breach highlights that the security of a hardware wallet is only as strong as the weakest link in the supply chain. Customers who chose Trezor partly because of its strong privacy stance may now reconsider whether the convenience of direct‑to‑consumer shipping is worth the risk of having their purchase history linked to their real identities. The incident also raises questions about how many other fulfillment partners retain customer data beyond agreed‑upon periods, and whether the cryptocurrency industry as a whole needs stronger regulatory or contractual safeguards for third‑party data handling.

How Trezor Has Responded and What Affected Users Should Do Now

Trezor has notified all newly affected customers directly from the official email address [email protected]. Customers who did not receive a notification are not considered impacted by this breach. The company has reiterated that its own infrastructure was not compromised and that no wallet funds, private keys, or recovery seeds were exposed. However, the practical advice for affected users is clear: be extremely suspicious of any unsolicited emails, phone calls, text messages, or physical mail that claims to be from Trezor or any cryptocurrency service. Never enter your recovery seed into a website, mobile app, or email response, regardless of how official the request appears. Trezor will never ask for a recovery seed, and legitimate support interactions will never require you to disclose it.

Practical Steps for Mitigating Phishing Risk

Users whose information was exposed should enable two‑factor authentication (2FA) on all cryptocurrency exchange and wallet accounts, change passwords for any services where they reuse the same login credentials, and monitor their emails for anomalous activity. Because the exposed data includes phone numbers and addresses, users should also be alert for SIM‑swapping attacks — in which attackers convince a mobile carrier to port a victim’s number to a new SIM — and consider placing a fraud alert on their credit report if they have concerns about identity theft. While the breach itself does not compromise crypto assets, the follow‑on attacks it enables can be devastating.

The Broader Industry Context: Vendor Risk Management in Crypto Custody

The Trezor‑ShipMonk breach serves as a case study in the challenges of vendor risk management for companies that handle sensitive customer data in the cryptocurrency ecosystem. Hardware wallet manufacturers, exchanges, and custodians all rely on third parties for logistics, customer support, payment processing, and identity verification. Each of these relationships creates a potential attack surface that is often harder to secure than the company’s own systems. The incident also highlights the tension between operational convenience and data minimization: while it may be tempting for fulfillment partners to retain historical order data for analytics, returns management, or customer service, that same data becomes a liability the moment a breach occurs.

What the Regulatory Landscape Might Look Like After This Breach

In the United States, data breach notification laws vary by state, and the exposure of 67,000 US residents may trigger reporting obligations in multiple jurisdictions. The breach also comes at a time when regulators are increasingly scrutinizing the data-handling practices of cryptocurrency companies and their partners. The Federal Trade Commission (FTC) and state attorneys general could investigate whether ShipMonk’s failure to delete data as promised constitutes an unfair or deceptive practice, particularly if customers were not informed that their data would be retained indefinitely. For the broader crypto industry, this incident may accelerate calls for stricter contractual penalties for data retention violations and more frequent third‑party security audits.

The revelation that an additional 67,000 US customers had their data exposed — and that this data should have been deleted years ago — underscores a fundamental truth about the modern digital economy: a company’s security posture is only as strong as the weakest link in its supply chain. Trezor’s hardware wallets may remain among the most secure options for cold storage, but the breach at ShipMonk reminds every user that the offline security of a device can be undermined by the online and physical‑world data trails left behind during the purchase process. As attackers grow more sophisticated in their targeting of cryptocurrency holders, the industry must evolve its approach to vendor risk — moving from contractual promises to verifiable compliance, and from minimal disclosure to maximum transparency when things go wrong. For the 67,000 US customers now added to the list of those exposed, the immediate threat is not to their private keys, but to the trust that their personal information would be handled responsibly. Regaining that trust will take far longer than the time it took ShipMonk to delete a database.

Share This Article