Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Trezor data breach expands to over 80,000 customers after ShipMonk retained deleted records
00

Trezor data breach expands to over 80,000 customers after ShipMonk retained deleted records

Sep 4, 2026

Trezor has revealed that a data breach at its shipping provider, ShipMonk, is far larger than initially reported, exposing approximately 67,000 additional U.S. customers. This expansion brings the total affected to over 80,000. The breach occurred because ShipMonk retained order records from 2019 to 2021 despite giving Trezor written assurances that they had been deleted. While Trezor emphasizes that its hardware wallets and private keys remain secure, the exposure of names, phone numbers, and physical addresses raises serious concerns over targeted phishing and physical safety.

ShipMonk data breach expansion

  • ▪The ShipMonk data breach originated from the zero-day exploitation of CVE-2026-72898, a critical SQL injection vulnerability in Metabase, which was reportedly executed by the ShinyHunters extortion gang.
  • ▪Trezor disclosed on September 4, 2026, that a data breach at its shipping provider ShipMonk exposed the personal information of approximately 67,000 additional United States customers.
  • ▪ShipMonk notified Trezor of the initial breach on August 10, 2026, and subsequently informed Trezor on September 2, 2026, that the breach was larger than previously reported.

Data retention policy failure

  • ▪Trezor is working to arrange an additional audit of ShipMonk and has deferred deciding the future of their partnership until obtaining a complete picture of the incident.
  • ▪Trezor maintains a data retention policy mandating that fulfillment partners delete or anonymize customer order information within 90 days following successful delivery.
  • ▪Trezor stated that ShipMonk retained customer records from orders placed between November 2019 and August 2021 despite repeatedly providing written assurances that the data had been deleted.

Customer exposure scope

  • ▪The newly exposed ShipMonk records include customer names, email addresses, phone numbers, shipping addresses, and order numbers.
  • ▪The addition of approximately 67,000 customers brings the total number of Trezor users affected by the ShipMonk breach to more than 80,000, up from the 13,689 disclosed in August 2026.
  • ▪Trezor previously experienced a security incident in January 2024 that exposed the contact details of approximately 66,000 users who had contacted its support desk since December 2021.

Phishing risks

  • ▪According to blockchain security firm Hacken, phishing and social engineering scams accounted for $306 million of the $482 million stolen across the cryptocurrency industry in the first quarter of 2026.
  • ▪Trezor warned that the leaked shipping addresses, phone numbers, and order details could expose affected individuals to physical security risks and highly targeted phishing or impersonation scams.

Trezor security assurances

  • ▪To mitigate future third-party data risks, Trezor is promoting an Anonymous Delivery system featuring locker pickups and automatic deletion of shipping identifiers, targeting a U.S. rollout by the end of 2026.
  • ▪Trezor emphasized that its internal systems, devices, private keys, and wallet backups were not compromised in the ShipMonk breach, and customer cryptocurrency funds remain secure.

Debatable claims

  • ▪Physical security risks of hardware wallets outweigh their digital benefits
  • ▪Hardware wallet companies should be held legally liable for data breaches at their third-party vendors
  • ▪Cryptocurrency hardware wallet manufacturers should be prohibited from retaining customer shipping data

8 sources

Ambcrypto
Trezor data breach expands to over 80,000 customers after ShipMonk kept old records - AMBCrypto
View source article
Unchainedcrypto
Trezor Says Shipping Partner Kept Customer Data It Certified as Deleted, Exposing 67,000 More - Unchained
View source article
Thehackernews
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
View source article
Cryptotimes
Trezor Breach Explodes as 67,000 More U.S Customers Are Exposed
View source article
Protos
Trezor says mailing breach leaked 67K more users than first thought
View source article

Story comments

Loading comments…

Related entities

United States

Related Projects

Trezor

Topics

Crypto privacy & surveillanceBitcoin wallets & custodyCrypto security