Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2026-72898 Vulnerabilities

Trezor ShipMonk Breach Expands as 67,000 More U.S. Customers Have Data Exposed

Trezor has disclosed that an additional 67,000 U.S. customers were affected by a data breach at its third-party shipping provider, ShipMonk, significantly expanding the scope of an incident first reported in August.

The newly identified records belong to customers who placed orders between November 2019 and August 2021. Exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers.

The disclosure is particularly concerning because Trezor says it had repeatedly received written confirmation from ShipMonk that the older customer records had been deleted in accordance with contractual and data-retention requirements. The company later discovered that the information remained in ShipMonk's systems.

What Happened?

Trezor initially disclosed the ShipMonk-related breach in August, reporting that approximately 13,689 customers had been affected.

On September 2, ShipMonk reportedly provided Trezor with an update indicating that the incident involved additional historical customer records. Trezor subsequently disclosed that approximately 67,000 additional U.S. customers were affected.

The expanded disclosure brings the total number of affected customers to more than 80,000, based on the figures publicly reported so far.

Key Facts

Category Details
Affected organization Trezor
Third-party provider ShipMonk
Newly affected customers ~67,000
Previously disclosed customers ~13,689
Newly affected region United States
Order period November 2019 – August 2021
Exposed information Names, emails, phone numbers, shipping addresses, order numbers
Trezor systems compromised? No, according to Trezor
Hardware wallets compromised? No, according to Trezor
Primary risks Phishing, impersonation, fraud and potential physical-security threats

The Data Was Supposed to Be Deleted

One of the most significant aspects of the incident is not simply the breach itself, but the apparent failure to enforce data-retention requirements.

Trezor says it had repeatedly requested that ShipMonk delete customer information and received written assurances confirming that the data had been removed.

However, the company later learned that the historical records were still present when the ShipMonk environment was compromised.

This raises broader questions about third-party risk management, data-retention controls and verification of contractual security requirements.

A contractual requirement to delete customer information provides little protection if organizations do not independently verify that the deletion has actually occurred.

What Information Was Exposed?

The newly disclosed records reportedly contained:

  • Full names
  • Email addresses
  • Phone numbers
  • Shipping addresses
  • Order numbers

The combination of these details creates a particularly useful dataset for targeted social engineering.

An attacker could potentially identify an individual by name, determine where a Trezor device was delivered, and use knowledge of the customer's purchase to make fraudulent communications appear legitimate.

Trezor Devices Remain Secure

Trezor has emphasized that the breach occurred within its third-party logistics ecosystem and did not compromise Trezor's own systems or hardware wallets.

The exposed information also does not indicate that customers' wallet recovery seeds or private keys were compromised.

However, the absence of wallet compromise does not eliminate the security risk.

The leaked information could allow criminals to identify people who purchased cryptocurrency hardware wallets and subsequently target them with highly convincing phishing attempts.

Phishing and Physical Security Risks

Trezor is warning affected customers to be particularly cautious about unsolicited communications.

Potential attacks could include:

  1. Phishing emails
  • Attackers may impersonate Trezor and request account information or direct victims to fraudulent websites.
  1. Fraudulent phone calls
  • Criminals could use exposed phone numbers and order information to make convincing support-related calls.
  1. Physical letters
  • Attackers could send fraudulent correspondence to addresses associated with Trezor purchases.
  1. Targeted cryptocurrency scams
  • Knowing that someone purchased a hardware wallet can make them a more attractive target for cryptocurrency-focused social engineering.

Security researchers have also highlighted the possibility of physical-security risks when attackers can associate a cryptocurrency user with a residential address.

A Supply-Chain Security Problem

The incident highlights a common challenge in modern cybersecurity: organizations increasingly depend on third-party providers to process, store and transport customer information.

Even when the primary company's infrastructure remains secure, sensitive information can still be exposed through:

  1. Logistics providers
  2. SaaS platforms
  3. Customer-support systems
  4. Marketing platforms
  5. Analytics services
  6. Cloud providers
  7. Payment processors

The Trezor incident demonstrates why vendor security assessments and data lifecycle management need to extend beyond initial onboarding.

Organizations should not only ask vendors how data is protected—they should also verify that data is deleted when it is no longer required.

How Customers Should Protect Themselves

Affected and potentially affected customers should take several precautions.

  1. Be suspicious of unsolicited communications
  • Do not trust emails, calls or messages simply because the sender knows your name, address or Trezor order information.
  1. Never share your recovery seed
  • A legitimate Trezor representative should never ask for your wallet recovery seed or private keys.

  • Treat any request for recovery words as a major red flag.

  1. Verify messages independently
  • If you receive a message claiming to be from Trezor, avoid clicking links in the message.

  • Instead, access Trezor's official website directly using a known address.

  1. Watch for targeted scams

Be particularly cautious of messages referring to:

  • Your previous Trezor order
  • A delivery problem
  • A refund
  • A security update
  • Wallet verification
  • Account recovery
  • Cryptocurrency transactions
  1. Consider physical-security implications
  • Customers whose residential addresses were exposed should remain aware that the information could potentially be used for targeted physical threats.

What Organizations Can Learn From the Incident

For security and compliance teams, the breach provides several important lessons.

Verify data deletion

Do not rely solely on vendor statements confirming that data has been deleted.

Organizations should establish processes for validating deletion or anonymization, particularly for sensitive customer information.

Strengthen third-party risk management

Vendor assessments should cover:

  • Data retention
  • Data deletion
  • Access controls
  • Incident response
  • Sub-processors
  • Logging and monitoring
  • Security certifications
  • Breach notification requirements
  • Minimize retained information

If historical customer information is no longer required for operational or legal purposes, retaining it indefinitely increases the potential impact of a future breach.

Monitor the supply chain

Security monitoring should extend to critical third-party services wherever possible, particularly vendors handling personally identifiable information.

Bottom Line

The Trezor-ShipMonk incident is a reminder that customer data can remain a security liability long after a transaction is completed.

While Trezor says its systems and hardware wallets remain secure, the exposure of names, contact information, shipping addresses and order details creates a significant opportunity for targeted phishing, impersonation and potentially physical-security attacks.

More importantly, the incident highlights a fundamental third-party security lesson: data-retention policies are only effective when organizations can verify that vendors actually follow them.

As the investigation continues, affected customers should remain alert for suspicious communications and avoid sharing wallet recovery information under any circumstances.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

critical CVE-2026-5430 Vulnerabilities

Hackers Exploit Critical WSO2 API Manager JWT Flaw Using Forged Admin Tokens

Security researchers have detected active exploitation attempts targeting a critical authentication-bypass vulnerability in WSO2 API Manager, with attackers sending forged JSON Web Tokens (JWTs) containing administrator privileges.

critical CVE-2026-85046, CVE-2026-87491 and CVE-2 Vulnerabilities

China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy GRIMWEDGE Backdoor

China-linked threat actors have been observed chaining multiple vulnerabilities in Google Chrome and Microsoft Windows as part of sophisticated cyber-espionage campaigns targeting non-governmental organizations and other high-value organizations.

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.