Cryptelio

Hacks & Exploits

Trezor Alerts 67,000 U.S. Customers of Data Breach Linked to Shipping Partner

Cryptelio Editorial Published 6 Sep 2026 · 08:30 UTC

Trezor, a prominent hardware wallet manufacturer, has issued notifications to approximately 67,000 U.S. customers regarding an expanded data breach. This breach stems from an incident involving its former shipping partner, ShipMonk.

On September 2, ShipMonk revealed that order records from November 2019 through August 2021 were still present in its systems, despite previous assurances that such data had been deleted. The compromised information includes full names, email addresses, phone numbers, shipping addresses, and order numbers.

Trezor expressed disappointment over ShipMonk's failure to adhere to their contractual obligations regarding data retention and deletion. The company stated, “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data.”

While Trezor's own systems and hardware wallets remain secure, the company has warned customers about increased risks of phishing and physical security threats due to the leaked information. Affected customers received direct email notifications, while those who did not are not included in this breach.

This incident adds to a smaller set of exposures first disclosed on August 13, highlighting ongoing concerns about data security in the cryptocurrency sector.

FAQ

What caused the data breach involving Trezor customers?

The data breach was caused by an incident involving Trezor's former shipping partner, ShipMonk, which revealed that order records from November 2019 through August 2021 were still present in its systems.

What type of information was compromised in the Trezor data breach?

The compromised information includes full names, email addresses, phone numbers, shipping addresses, and order numbers of approximately 67,000 U.S. customers.

How did Trezor respond to the data breach?

Trezor expressed disappointment over ShipMonk's failure to adhere to their contractual obligations regarding data retention and deletion, and they have warned customers about increased risks of phishing and physical security threats.

Are Trezor's systems and hardware wallets secure following the breach?

Yes, Trezor stated that their own systems and hardware wallets remain secure despite the data breach.

What should affected customers do after receiving a notification about the breach?

Affected customers should be vigilant about potential phishing attempts and take necessary precautions to protect their personal information.

Read story →