{"id":79919,"date":"2026-09-05T12:12:16","date_gmt":"2026-09-05T16:12:16","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=79919"},"modified":"2026-09-05T12:12:16","modified_gmt":"2026-09-05T16:12:16","slug":"trezor-shipmonk-data-breach-79919","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/trezor-shipmonk-data-breach-79919\/","title":{"rendered":"Trezor Reveals Additional 67,000 US Customers Exposed"},"content":{"rendered":"<p>Trezor&#8217;s disclosure that a <a href=\"https:\/\/overcentral.com\/en\/safepal-data-breach-customer-records\/\" title=\"SafePal Data Breach Impacts 40,000 Customers\" data-iacss-internal=\"1\">data breach<\/a> at its logistics partner <a href=\"https:\/\/www.shipmonk.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">ShipMonk<\/a> exposed the <a href=\"https:\/\/overcentral.com\/en\/hasbro-data-breach-employee-information-exposed-2024-78578\/\" title=\"Hasbro Data Breach Exposes Employee Personal Information\" data-iacss-internal=\"1\">personal information<\/a> of an additional 67,000 customers in the United States has sharply escalated what initially appeared to be a contained incident, raising serious questions about third-party data-retention practices and the long-term security risks facing cryptocurrency hardware wallet users. The newly identified records, which <a href=\"https:\/\/trezor.io\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Trezor<\/a> announced on September 4, 2026, nearly triple the previously reported impact and reveal that ShipMonk had retained customer data for years beyond the contractual deletion requirements \u2014 a failure that now exposes a far larger pool of individuals to phishing, physical surveillance, and targeted social engineering attacks.<\/p>\n<h2>ShipMonk Breach Expands to Include Order Data Dating Back to 2019<\/h2>\n<p>The hardware wallet manufacturer, a subsidiary of SatoshiLabs, first disclosed the incident on August 13, 2026, after ShipMonk reported unauthorized access to systems containing Trezor order information. At that time, Trezor said 13,689 customers across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal were affected, with the bulk of exposures limited to orders placed between May 10 and August 8, 2026. That initial assessment assumed that ShipMonk had complied with a contractual requirement to delete or anonymize customer information after 90 days, a standard safeguard intended to minimize the blast radius of any future compromise.<\/p>\n<h3>A Delayed Discovery of Retained Historical Data<\/h3>\n<p>On September 2, ShipMonk notified Trezor that the breach was far more extensive. An additional 67,000 US customers who ordered Trezor products between November 2019 and August 2021 had their names, email addresses, phone numbers, shipping addresses, and order numbers exposed. Trezor stated that it had repeatedly received written assurances from ShipMonk during their partnership that older customer data had been deleted in accordance with contractual terms and the company&#8217;s own data retention policy. The retention of this historical data \u2014 spanning nearly two years of orders from more than half a decade ago \u2014 contradicts those assurances and suggests either a systemic failure within ShipMonk&#8217;s data governance or a deliberate choice to keep records for reasons that remain unclear.<\/p>\n<h3>What Information Was Exposed in the Trezor-ShipMonk Breach?<\/h3>\n<p><a href=\"https:\/\/overcentral.com\/en\/for-the-stars-space-exploration-game-78319\/\" title=\"For The Stars Reveals Vast Universe to Explore and Settle\" data-iacss-internal=\"1\">For the<\/a> newly identified 67,000 US customers, the exposed data includes names, email addresses, phone numbers, shipping addresses, and order numbers. This is the same category of personal identifiable information (PII) that was compromised in the initial 13,689-customer incident. No wallet backups, private keys, recovery seeds, or device-level data were accessed, as Trezor\u2019s own infrastructure and hardware wallets were not affected. However, the combination of cryptocurrency-related purchase history with full contact details creates a uniquely dangerous threat profile, because attackers can now create sophisticated, personalized phishing campaigns aimed at individuals who are known to own hardware wallets.<\/p>\n<h2>The Phishing and Physical Security Risk: Why Exposure Matters Beyond the PII<\/h2>\n<p>Cryptocurrency hardware wallets, like those produced by Trezor, are designed to store private keys offline, making remote theft of funds extremely difficult unless the attacker can trick the user into revealing their recovery seed or approving a malicious transaction. The ShipMonk breach does not provide any direct access to wallet funds, but it arms cybercriminals with precisely the kind of context that makes social engineering effective. Attackers who know a target\u2019s name, address, phone number, and email \u2014 and who know that the target owns a Trezor device \u2014 can impersonate Trezor support, wallet developers, or even law enforcement with a high degree of credibility.<\/p>\n<h3>Concrete Attack Scenarios in the Wake of the Breach<\/h3>\n<p>A user who receives a call from someone claiming to be a Trezor security agent, referencing their recent order history and shipping address, may be far more likely to comply with a request to visit a fraudulent website or disclose their recovery seed. Similarly, physical letters or packages containing fake hardware replacements could be mailed to exposed addresses, instructing recipients to plug in the device or visit a phishing URL. Because the exposed data spans orders from as far back as 2019, some customers may no longer own the same phone number \u2014 but attackers can still cross\u2011reference shipped addresses, emails, and names to build detailed profiles. The long tail of this breach means that individuals who purchased a Trezor half a decade ago remain at heightened risk for years to come.<\/p>\n<h2>Supply Chain Data Governance: A Recurring Failure in the Crypto Industry<\/h2>\n<p>The Trezor incident is not the first time a cryptocurrency company has been let down by a third\u2011party logistics provider, but the scale and duration of unauthorized data retention make this case particularly egregious. Trezor had negotiated contractual data deletion timelines of 90 days, a standard clause in data processing agreements that is intended to limit exposure. ShipMonk\u2019s failure to comply \u2014 over a five\u2011year period \u2014 indicates either a lack of automated deletion processes, inadequate auditing by ShipMonk, or a deliberate policy of retaining historical data for analytics or operational purposes. Trezor\u2019s statement that it \u201crepeatedly received written assurances\u201d underscores a broader industry problem: contractual obligations around data deletion are notoriously difficult to enforce, and few companies have the resources or leverage to conduct regular, independent audits of their vendors\u2019 databases.<\/p>\n<h3>Implications for the Hardware Wallet Market and User Trust<\/h3>\n<p>For Trezor, which has cultivated a reputation for security\u2011first design, the ShipMonk incident could erode user trust, particularly among privacy\u2011conscious cryptocurrency users. While the company\u2019s own products remain uncompromised, the breach highlights that the security of a hardware wallet is only as strong as the weakest link in the supply chain. Customers who chose Trezor partly because of its strong privacy stance may now reconsider whether the convenience of direct\u2011to\u2011consumer shipping is worth the risk of having their purchase history linked to their real identities. The incident also raises questions about how many other fulfillment partners retain customer data beyond agreed\u2011upon periods, and whether the cryptocurrency industry as a whole needs stronger regulatory or contractual safeguards for third\u2011party data handling.<\/p>\n<h2>How Trezor Has Responded and What Affected Users Should Do Now<\/h2>\n<p>Trezor has notified all newly affected customers directly from the official email address help@trezor.io. Customers who did not receive a notification are not considered impacted by this breach. The company has reiterated that its own infrastructure was not compromised and that no wallet funds, private keys, or recovery seeds were exposed. However, the practical advice for affected users is clear: be extremely suspicious of any unsolicited emails, phone calls, text messages, or physical mail that claims to be from Trezor or any cryptocurrency service. Never enter your recovery seed into a website, mobile app, or email response, regardless of how official the request appears. Trezor will never ask for a recovery seed, and legitimate support interactions will never require you to disclose it.<\/p>\n<h3>Practical Steps for Mitigating Phishing Risk<\/h3>\n<p>Users whose information was exposed should enable two\u2011factor authentication (2FA) on all cryptocurrency exchange and wallet accounts, change passwords for any services where they reuse the same login credentials, and monitor their emails for anomalous activity. Because the exposed data includes phone numbers and addresses, users should also be alert for SIM\u2011swapping attacks \u2014 in which attackers convince a mobile carrier to port a victim\u2019s number to a new SIM \u2014 and consider placing a fraud alert on their credit report if they have concerns about identity theft. While the breach itself does not compromise crypto assets, the follow\u2011on attacks it enables can be devastating.<\/p>\n<h2>The Broader Industry Context: Vendor Risk Management in Crypto Custody<\/h2>\n<p>The Trezor\u2011ShipMonk breach serves as a case study in the challenges of vendor risk management for companies that handle sensitive customer data in the cryptocurrency ecosystem. Hardware wallet manufacturers, exchanges, and custodians all rely on third parties for logistics, customer support, payment processing, and identity verification. Each of these relationships creates a potential attack surface that is often harder to secure than the company\u2019s own systems. The incident also highlights the tension between operational convenience and data minimization: while it may be tempting for fulfillment partners to retain historical order data for analytics, returns management, or customer service, that same data becomes a liability the moment a breach occurs.<\/p>\n<h3>What the Regulatory Landscape Might Look Like After This Breach<\/h3>\n<p>In the United States, data breach notification laws vary by state, and the exposure of 67,000 US residents may trigger reporting obligations in multiple jurisdictions. The breach also comes at a time when regulators are increasingly scrutinizing the data-handling practices of cryptocurrency companies and their partners. The Federal Trade Commission (FTC) and state attorneys general could investigate whether ShipMonk\u2019s failure to delete data as promised constitutes an unfair or deceptive practice, particularly if customers were not informed that their data would be retained indefinitely. For the broader crypto industry, this incident may accelerate calls for stricter contractual penalties for data retention violations and more frequent third\u2011party security audits.<\/p>\n<p>The revelation that an additional 67,000 US customers had their data exposed \u2014 and that this data should have been deleted years ago \u2014 underscores a fundamental truth about the modern digital economy: a company\u2019s security posture is only as strong as the weakest link in its supply chain. Trezor\u2019s hardware wallets may remain among the most secure options for cold storage, but the breach at ShipMonk reminds every user that the offline security of a device can be undermined by the online and physical\u2011world data trails left behind during the purchase process. As attackers grow more sophisticated in their targeting of cryptocurrency holders, the industry must evolve its approach to vendor risk \u2014 moving from contractual promises to verifiable compliance, and from minimal disclosure to maximum transparency when things go wrong. For the 67,000 US customers now added to the list of those exposed, the immediate threat is not to their private keys, but to the trust that their personal information would be handled responsibly. Regaining that trust will take far longer than the time it took ShipMonk to delete a database.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Trezor&#8217;s disclosure that a data breach at its logistics partner ShipMonk exposed the personal information of an additional 67,000 customers in the United States has sharply escalated what initially appeared to be a contained incident, raising serious questions about third-party data-retention practices and the long-term security risks facing cryptocurrency hardware wallet users. The newly identified [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":82986,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/79919.png","fifu_image_alt":"Trezor Reveals Additional 67,000 US Customers Exposed","footnotes":""},"categories":[40668],"tags":[],"class_list":["post-79919","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/79919.png","fifu_image_alt":"Trezor Reveals Additional 67,000 US Customers Exposed","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/79919","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=79919"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/79919\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/82986"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=79919"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=79919"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=79919"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}