Hacks & Exploits
Trezor Reveals Additional 67,000 US Customers Affected by ShipMonk Data Breach
Trezor has announced that the recent data breach involving its mailing partner ShipMonk has impacted an additional 67,000 US customers who placed orders between November 2019 and August 2021. This revelation brings the total number of affected users to over 80,000, following the initial disclosure of 13,689 customers.
The compromised data includes sensitive information such as names, email addresses, phone numbers, shipping addresses, and order numbers. Affected customers span several countries, including the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
Trezor expressed disappointment that, despite receiving written assurances from ShipMonk regarding the deletion of customer data, it was later revealed that the data remained in ShipMonk’s systems. The company emphasized that its own systems and devices were not compromised in the breach.
In light of the breach, Trezor has urged affected users to be vigilant against potential phishing attempts and other targeted attacks. The company is also working on implementing anonymous delivery options to enhance customer privacy for future orders.
Trezor Data Breach Update
On September 4, 2026, Trezor announced that an additional 67,000 US customers had their personal data exposed due to a breach involving their shipping partner, ShipMonk. This brings the total number of affected customers to approximately 80,700.
The breach was traced to a SQL-injection vulnerability in ShipMonk's Metabase analytics platform, which allowed unauthorized access to customer records. The newly exposed records pertain to orders placed between 2019 and 2021, despite Trezor receiving assurances from ShipMonk that such data would be securely deleted.
Trezor emphasized that their core infrastructure remains secure, and private keys, device firmware, and wallet seed backups were not compromised. However, the exposed data poses risks for targeted social engineering attacks.
This incident follows previous breaches in January 2024 and April 2022, which affected approximately 66,000 and over 106,000 customers, respectively. Trezor is accelerating the rollout of an Anonymous Delivery option to enhance customer privacy.
Affected customers are advised to remain vigilant against phishing attempts and treat their phone numbers as compromised.
FAQ
What is the recent data breach involving Trezor and ShipMonk?
Trezor announced that a data breach involving its mailing partner ShipMonk has affected an additional 67,000 US customers who placed orders between November 2019 and August 2021, bringing the total number of affected users to over 80,000.
What type of data was compromised in the ShipMonk breach?
The compromised data includes sensitive information such as names, email addresses, phone numbers, shipping addresses, and order numbers.
Are Trezor's own systems and devices affected by the breach?
No, Trezor has emphasized that its own systems and devices were not compromised in the breach.
What should affected customers do in light of the breach?
Affected customers are urged to be vigilant against potential phishing attempts and other targeted attacks following the breach.
What measures is Trezor taking to enhance customer privacy in the future?
Trezor is working on implementing anonymous delivery options to enhance customer privacy for future orders.