Trezor Data Breach Grows to 80,000 Victims After Vendor Failed to Delete Data

Coinmama
Blockonomics


Trezor’s data breach just got a lot bigger. The hardware wallet maker confirmed on September 4 that roughly 67,000 additional U.S. customers were caught up in a security incident tied to its shipping provider, ShipMonk, pushing the total number of affected users far beyond what the company first disclosed weeks earlier. The revised figure turns what looked like a contained mishap into one of the more serious third-party data exposures the crypto hardware industry has seen this year.

Key takeaways

  • Trezor said another approximately 67,000 U.S. customers were affected by the ShipMonk data breach, on top of the roughly 14,000 initially reported in August.
  • Exposed records cover orders placed between November 2019 and August 2021 and include names, emails, phone numbers, shipping addresses, and order numbers.
  • Trezor said it repeatedly asked ShipMonk to delete the data and received written confirmation that it had been removed — but the data was never actually deleted.
  • Trezor’s own systems and hardware wallets were not compromised, according to the company.
  • All newly affected customers have been emailed and warned about scam risks and physical security concerns.

Expanded ShipMonk Data Breach Hits Over 67,000 Trezor Customers in the U.S.

The scope of the Trezor data breach expanded dramatically after ShipMonk told the company on September 2 that the incident was far bigger than first reported. Trezor initially disclosed the breach on August 13, saying about 14,000 customers had personal information exposed. That number has now jumped by another 67,000 U.S. customers, according to Trezor’s own statement and reporting from Cointelegraph and TheStreet.

Combined with the original disclosure, the total number of affected Trezor users worldwide now stands at more than 80,000, based on figures reported by TheStreet. The August batch had already broken down into 11,742 customers with full data exposure — names, emails, phone numbers, and shipping addresses — and 1,947 customers with partial exposure limited to names, cities, and email addresses.

This isn’t the first time Trezor has had to notify large groups of users about phishing-related risks. The company reported in January 2024 that roughly 66,000 users who had contacted its support team since December 2021 faced potential phishing exposure, according to Cointelegraph. The recurrence of large-scale customer notifications raises questions about how third-party vendors handle sensitive shipping and order data long after transactions are completed.

Tokenmetrics

Details and Timeline of Exposed Customer Data

The newly identified records span nearly two years of customer activity, covering orders placed between November 2019 and August 2021. For the affected U.S. customers, the exposed fields include full names, email addresses, phone numbers, shipping addresses, and order numbers — enough detail to build convincing phishing attempts or, in more troubling cases, to target someone’s home address directly.

That combination of data matters because hardware wallets are physical devices tied to real addresses. Unlike a stolen password, a leaked shipping address doesn’t expire and can’t be reset. Attackers with access to names, order details, and home addresses have historically used that information not just for email scams but for targeted phone calls and even physical letters designed to look official.

Trezor’s Data Deletion Efforts and ShipMonk’s Non-Compliance

Why did data from 2019 orders still exist in 2026? Trezor says it shouldn’t have. The company stated it had repeatedly asked ShipMonk to delete customer data throughout their business relationship and had received written assurances — in line with their contract and Trezor’s own data policy — that the information had been removed.

It wasn’t. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said in its disclosure. That single sentence captures the core failure at the heart of this incident: a documented, repeated deletion request that simply wasn’t honored on the vendor’s end.

Trezor’s original August disclosure noted that the breach’s initial scope a policy constraint obligated fulfillment partners to remove or render anonymous all order data within 90 days following delivery. The September update makes clear that policy existed on paper but wasn’t consistently enforced in practice — at least not for the older order batches now coming to light.

Why this matters: The episode is a reminder that a company’s own security posture is only as strong as its weakest third-party contractor. Trezor’s hardware and firmware were never touched, but customers still ended up exposed because a shipping partner held onto data it was contractually obligated to delete.

Impact on Security and Customer Notifications

Trezor has been clear on one point: its own infrastructure was not compromised, and hardware wallets themselves remain secure. The breach originated entirely on ShipMonk’s side, affecting order and shipping records rather than any wallet seed phrases, private keys, or device firmware.

Still, Trezor emailed every customer affected by the latest disclosure and warned them to stay alert for scam emails, fraudulent phone calls, and suspicious letters. The company also flagged potential physical security risks tied to exposed home addresses — a warning that echoes concerns raised after similar incidents elsewhere in the hardware wallet space.

The most relevant precedent is Ledger’s 2020 breach, which exposed information belonging to more than 270,000 customers, including names, emails, phone numbers, and in some cases home addresses that were later published on a hacking forum. Years later, Ledger customers have continued to report scam phone calls and physical letters referencing that leaked data — a pattern that shows how long-lived the fallout from these breaches can be.

That history is exactly why security researchers treat exposed shipping data differently from a typical password leak. Phishing attempts tied to crypto hardware wallets tend to persist for years, not weeks, because attackers know victims likely still own the devices tied to the leaked orders.

FAQ

How many Trezor customers were impacted by the ShipMonk data breach?

Initially, about 14,000 customers were reported affected. After ShipMonk’s update, approximately 67,000 additional U.S. customers were found to be impacted, pushing the total well past 80,000 worldwide.

What customer data was compromised in the ShipMonk breach?

The exposed data includes customer names, emails, phone numbers, shipping addresses, and order numbers from orders placed between November 2019 and August 2021.

Did Trezor’s own systems or hardware wallets get compromised?

No. Trezor said its own systems were not compromised and its hardware wallets remain secure. The breach was limited to shipping and order data held by ShipMonk.

What actions did Trezor take after discovering the breach?

Trezor repeatedly requested that ShipMonk delete customer data and received written assurances that it had been removed. After learning the data hadn’t actually been deleted, the company notified all affected customers and warned them about potential scams and physical security risks.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.



Source link

BTCC

Be the first to comment

Leave a Reply

Your email address will not be published.


*