Skip to main content
Emerging ThreatsData Breaches

Trezor Breach Widens to 81,000 Customers

Workers handle packages in a brightly-lit logistics facility with rows of boxes and a computer terminal in the background.

67,000 more customers than originally reported were swept up in a ShipMonk data theft that Trezor now says affects 81,000 of its users.

Scope and scale: 81,000 customers and exposed personal details

In an update posted on September 4, Trezor disclosed that the trove stolen from logistics partner ShipMonk included order data stretching well beyond the company’s initial assessment. The firm said the breach exposed customer names, emails, phone numbers, shipping addresses and order numbers. In its public notice Trezor warned: “Be aware of the increased risk of phishing.” The company said the leaked information “could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks.”

Timeline: initial notification on August 13 and the September 4 expansion

Trezor first posted a breach notification on August 13 that described data from May 10 to August 8, 2026 as involved. On September 4 the company said it had been informed the stolen dataset also contained order records dating from November 2019 through August 2021. Trezor’s revised calculation pushed the victim count sharply upward — the firm reported the new total represents a 479% increase on the original estimate.

ShipMonk’s role and Trezor’s contractual expectations

Trezor laid responsibility for the incident at the feet of its shipping partner, saying that ShipMonk did not follow the data minimization requirements set by contract. Trezor wrote on X (formerly Twitter): “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”

The company said it is “in direct contact with ShipMonk to establish exactly what happened and which data was reached.” According to Trezor, ShipMonk “has secured the affected systems and hardened its security after the incident,” and Trezor is still deciding whether to take legal action against the firm.

Risks to customers: phishing, fraud and the shadow of earlier scams

Trezor’s advisory to affected customers stressed elevated phishing risk and the potential for fraud and physical threats, echoing what the company called the likely uses for the leaked fields: scam emails, fraudulent calls or letters, and possible physical security risks. The firm’s warning arrives against a backdrop of earlier targeting: in 2022 Trezor was forced to clarify that an email warning of a major data breach was itself a scam, designed to trick customers into surrendering their wallet recovery codes.

What this means for end users, security teams, and logistics partners

  • End users — Trezor told customers to anticipate an “increased risk of phishing.” It also recommended minimizing what personal data they share and suggested options such as using a PO box, parcel locker, or pickup point to limit delivery data exposure.
  • Security teams and technologists — the company’s disclosure highlights that order and shipping datasets can persist outside vendor expectations; Trezor said it had repeatedly requested and received written assurances of data deletion that were not honored, drawing attention to the need to verify deletion and retention practices with suppliers.
  • Logistics partners — ShipMonk has reportedly secured the affected systems and “hardened its security” after the incident; Trezor noted it is in direct contact with ShipMonk to determine what was accessed and is considering legal remedies tied to contractual data policies.

Trezor’s immediate mitigations and next steps

Beyond the public advisories, Trezor said it is accelerating work on “anonymous delivery” in its online shop so that less personal data will leave its systems in future orders. In the short term the company urged customers to use delivery alternatives — PO boxes, parcel lockers or pickup points — to keep what they share to a minimum. Trezor also stated it is still deciding whether to pursue legal action and is working with ShipMonk to “establish exactly what happened and which data was reached.”

The expanded disclosure shifts this event from a recent short-window exposure to a broader, multi-year dataset and raises the immediate practical question Trezor itself has posed: which records were actually accessed, and will contractual assurances lead to remedial action or litigation? The company and its shipping partner now control the next facts to be revealed.

Original story at Infosecurity Magazine