Trezor ShipMonk Breach Expands as 67,000 More U.S. Customers Have Data Exposed
Trezor has disclosed that an additional 67,000 U.S. customers were affected by a data breach at its third-party shipping provider, ShipMonk, significantly expanding the scope of an incident first reported in August.

The newly identified records belong to customers who placed orders between November 2019 and August 2021. Exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers.
The disclosure is particularly concerning because Trezor says it had repeatedly received written confirmation from ShipMonk that the older customer records had been deleted in accordance with contractual and data-retention requirements. The company later discovered that the information remained in ShipMonk's systems.
What Happened?
Trezor initially disclosed the ShipMonk-related breach in August, reporting that approximately 13,689 customers had been affected.
On September 2, ShipMonk reportedly provided Trezor with an update indicating that the incident involved additional historical customer records. Trezor subsequently disclosed that approximately 67,000 additional U.S. customers were affected.
The expanded disclosure brings the total number of affected customers to more than 80,000, based on the figures publicly reported so far.
Key Facts
| Category | Details |
|---|---|
| Affected organization | Trezor |
| Third-party provider | ShipMonk |
| Newly affected customers | ~67,000 |
| Previously disclosed customers | ~13,689 |
| Newly affected region | United States |
| Order period | November 2019 – August 2021 |
| Exposed information | Names, emails, phone numbers, shipping addresses, order numbers |
| Trezor systems compromised? | No, according to Trezor |
| Hardware wallets compromised? | No, according to Trezor |
| Primary risks | Phishing, impersonation, fraud and potential physical-security threats |
The Data Was Supposed to Be Deleted
One of the most significant aspects of the incident is not simply the breach itself, but the apparent failure to enforce data-retention requirements.
Trezor says it had repeatedly requested that ShipMonk delete customer information and received written assurances confirming that the data had been removed.
However, the company later learned that the historical records were still present when the ShipMonk environment was compromised.
This raises broader questions about third-party risk management, data-retention controls and verification of contractual security requirements.
A contractual requirement to delete customer information provides little protection if organizations do not independently verify that the deletion has actually occurred.
What Information Was Exposed?
The newly disclosed records reportedly contained:
- Full names
- Email addresses
- Phone numbers
- Shipping addresses
- Order numbers
The combination of these details creates a particularly useful dataset for targeted social engineering.
An attacker could potentially identify an individual by name, determine where a Trezor device was delivered, and use knowledge of the customer's purchase to make fraudulent communications appear legitimate.
Trezor Devices Remain Secure
Trezor has emphasized that the breach occurred within its third-party logistics ecosystem and did not compromise Trezor's own systems or hardware wallets.
The exposed information also does not indicate that customers' wallet recovery seeds or private keys were compromised.
However, the absence of wallet compromise does not eliminate the security risk.
The leaked information could allow criminals to identify people who purchased cryptocurrency hardware wallets and subsequently target them with highly convincing phishing attempts.
Phishing and Physical Security Risks
Trezor is warning affected customers to be particularly cautious about unsolicited communications.
Potential attacks could include:
- Phishing emails
- Attackers may impersonate Trezor and request account information or direct victims to fraudulent websites.
- Fraudulent phone calls
- Criminals could use exposed phone numbers and order information to make convincing support-related calls.
- Physical letters
- Attackers could send fraudulent correspondence to addresses associated with Trezor purchases.
- Targeted cryptocurrency scams
- Knowing that someone purchased a hardware wallet can make them a more attractive target for cryptocurrency-focused social engineering.
Security researchers have also highlighted the possibility of physical-security risks when attackers can associate a cryptocurrency user with a residential address.
A Supply-Chain Security Problem
The incident highlights a common challenge in modern cybersecurity: organizations increasingly depend on third-party providers to process, store and transport customer information.
Even when the primary company's infrastructure remains secure, sensitive information can still be exposed through:
- Logistics providers
- SaaS platforms
- Customer-support systems
- Marketing platforms
- Analytics services
- Cloud providers
- Payment processors
The Trezor incident demonstrates why vendor security assessments and data lifecycle management need to extend beyond initial onboarding.
Organizations should not only ask vendors how data is protected—they should also verify that data is deleted when it is no longer required.
How Customers Should Protect Themselves
Affected and potentially affected customers should take several precautions.
- Be suspicious of unsolicited communications
- Do not trust emails, calls or messages simply because the sender knows your name, address or Trezor order information.
- Never share your recovery seed
A legitimate Trezor representative should never ask for your wallet recovery seed or private keys.
Treat any request for recovery words as a major red flag.
- Verify messages independently
If you receive a message claiming to be from Trezor, avoid clicking links in the message.
Instead, access Trezor's official website directly using a known address.
- Watch for targeted scams
Be particularly cautious of messages referring to:
- Your previous Trezor order
- A delivery problem
- A refund
- A security update
- Wallet verification
- Account recovery
- Cryptocurrency transactions
- Consider physical-security implications
- Customers whose residential addresses were exposed should remain aware that the information could potentially be used for targeted physical threats.
What Organizations Can Learn From the Incident
For security and compliance teams, the breach provides several important lessons.
Verify data deletion
Do not rely solely on vendor statements confirming that data has been deleted.
Organizations should establish processes for validating deletion or anonymization, particularly for sensitive customer information.
Strengthen third-party risk management
Vendor assessments should cover:
- Data retention
- Data deletion
- Access controls
- Incident response
- Sub-processors
- Logging and monitoring
- Security certifications
- Breach notification requirements
- Minimize retained information
If historical customer information is no longer required for operational or legal purposes, retaining it indefinitely increases the potential impact of a future breach.
Monitor the supply chain
Security monitoring should extend to critical third-party services wherever possible, particularly vendors handling personally identifiable information.
Bottom Line
The Trezor-ShipMonk incident is a reminder that customer data can remain a security liability long after a transaction is completed.
While Trezor says its systems and hardware wallets remain secure, the exposure of names, contact information, shipping addresses and order details creates a significant opportunity for targeted phishing, impersonation and potentially physical-security attacks.
More importantly, the incident highlights a fundamental third-party security lesson: data-retention policies are only effective when organizations can verify that vendors actually follow them.
As the investigation continues, affected customers should remain alert for suspicious communications and avoid sharing wallet recovery information under any circumstances.
Related reporting
Hackers Exploit Critical WSO2 API Manager JWT Flaw Using Forged Admin Tokens
Security researchers have detected active exploitation attempts targeting a critical authentication-bypass vulnerability in WSO2 API Manager, with attackers sending forged JSON Web Tokens (JWTs) containing administrator privileges.
Nintendo Switch Vulnerability Lets Nearby Attackers Run Unauthorized Code via QR Code Feature
Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could allow a nearby attacker to execute unauthorized code or access information stored on the console.
China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy GRIMWEDGE Backdoor
China-linked threat actors have been observed chaining multiple vulnerabilities in Google Chrome and Microsoft Windows as part of sophisticated cyber-espionage campaigns targeting non-governmental organizations and other high-value organizations.


