Breaking
SecurityDeveloping Story

Trezor Breach Widens to 81K Customers

Trezor says a breach at shipping partner ShipMonk now affects 81,000 customers, a 479% jump from initial estimates.

··6 hours ago·3 min read
a bitcoin on top of a computer motherboard
Photo by Michael Förtsch on Unsplash

The fallout from a breach at a shipping partner of cryptocurrency wallet maker Trezor is proving far larger than first disclosed. In an update posted on September 4, the company said the incident now affects 81,000 customers — a 479% increase over the initial estimate. The company reported the development in an update to its earlier breach notification.

Scope of the Breach Expands

Trezor originally reported on August 13 that data from between May 10 and August 8, 2026 was involved. The company has now been informed that the trove stolen from ShipMonk, its logistics partner, also includes order data from the period November 2019 through August 2021.

That expanded timeframe significantly increases the number of affected individuals. The breach notification now covers data that is over a year old, raising concerns about the longevity of the exposure.

What Data Was Exposed

According to Trezor, the compromised records include full customer details: names, emails, phone numbers, shipping addresses, and order numbers. This is the kind of information that can be used for targeted phishing campaigns.

In its update, Trezor warned customers to be vigilant. “Be aware of the increased risk of phishing,” the firm said. “The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks.”

History of Targeting

Trezor customers have long been a target for cybercriminals. In 2022, the company was forced to clarify that an email sent to customers warning of a major data breach was in fact a scam designed to trick them into handing over their wallet recovery codes.

That incident highlighted the specific risk to cryptocurrency users, whose digital assets can be drained if recovery phrases fall into the wrong hands.

The ShipMonk Connection

Trezor laid the blame for the latest breach squarely on ShipMonk. The company said its data minimization policy was not followed, despite repeated assurances from the logistics partner.

“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” Trezor wrote in a post on X (formerly Twitter). “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”

Response and Mitigation

Trezor said it is in direct contact with ShipMonk to establish exactly what happened and which data was accessed. According to the company, ShipMonk has secured the affected systems and hardened its security after the incident.

Trezor also said it is considering legal action against the logistics firm, though it has not yet decided whether to pursue it.

Steps for Affected Customers

In the meantime, Trezor is advising customers to be on guard for suspicious communications. The company also announced it is accelerating work on anonymous delivery options in its online shop, so that less personal data has to leave its systems in the future.

Until that feature is available, Trezor suggests customers minimize what they share by using a PO box, parcel locker, or pickup point when ordering.

Why It Matters

This incident underscores the outsized role that third-party vendors play in data security. For a hardware wallet manufacturer, whose promise rests on protecting users' digital assets, a breach at a shipping partner reveals that the 'cold storage' ethos doesn't extend to the physical delivery chain. Attackers who obtain shipping addresses and order histories may combine that data with social engineering to attempt wallet theft or other fraud.

Given the sensitivity of cryptocurrency-related personal data and the history of targeted phishing against Trezor customers, this larger exposure could lead to more sophisticated attacks. As Trezor works to fortify its processes and potentially pursue legal recourse, affected customers need to watch for unsolicited communications and verify any interactions that request sensitive information. For the broader industry, the episode highlights a vulnerability in the physical logistics layer of digital asset security, a facet that's often overlooked until an incident occurs.

#trezor#supply-chain#breach#shipmonk#cryptocurrency#phishing

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories