Key Points

  • Trezor announced on Friday that an additional 67,000 customers in the U.S. were affected by the ShipMonk data breach previously disclosed.
  • The compromised records span orders made from November 2019 to August 2021, including names, phone numbers, and addresses.
  • Trezor stated that it had consistently received written assurances from ShipMonk regarding the deletion of this data.

On Friday, Trezor revealed that another 67,000 of its U.S. customers had their personal information, including names, email addresses, phone numbers, home addresses, and order numbers, exposed due to a breach at the shipping company ShipMonk. This incident affects customers who placed orders between November 2019 and August 2021, meaning some of the exposed information is nearly seven years old. ShipMonk communicated this update just two days prior.

Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.

Another 67,000 customers from the US who ordered between November 2019 and August 2021… https://t.co/yDQvTlAA2S

— Trezor (@Trezor) September 4, 2026

Trezor had repeatedly requested and received confirmation in writing from ShipMonk that the affected records were deleted, adhering to their contractual agreement and data policy. The company expressed disappointment upon learning that this was not the case. Initially, Trezor had reported a smaller breach in August, which it attributed to a 90-day deletion policy negotiated with its fulfillment partners. However, the scale of the breach has now escalated significantly, with the number of affected customers rising from 13,689 to approximately 80,700.

Risks for Wallet Owners

It is important to note that Trezor's systems were not compromised, and the devices, private keys, and wallet backups remain secure. However, the breach poses risks as it reveals the identities of hardware wallet owners, potentially facilitating phishing attempts through emails, phone calls, and letters. Trezor cautioned customers about the heightened risks to their physical safety and reiterated that wallet backups should never be shared or entered on websites.

Both Trezor and its competitor Ledger had already reported instances of fraudulent letters being sent to their customers in February, featuring holograms, QR codes, and forged signatures, urging them to activate a nonexistent security check to retain access to their wallets.

Cybercrime expert David Sehyeon Baek previously commented that letters containing personal names and addresses signify a physical threat, and noted that stolen data can remain valuable for years since individuals seldom change their contact information.

Myriad: Where does Ethereum price go next? Click to make your prediction.

The breach is attributed to a critical SQL injection vulnerability in the analytics tool Metabase, disclosed on August 6, which allowed unauthorized attackers to obtain credentials for connected databases. Other companies, including laptop manufacturer Framework and form builder Tally, were also impacted by this security issue. Reports indicate that ShipMonk has received extortion emails linked to the hacker group ShinyHunters, although this attribution remains unverified.

Trezor has announced plans to expedite the implementation of anonymous delivery options, allowing customers to use locker pickups, neutral packaging, and generic sender details to avoid disclosing their home addresses altogether.

Daily Debrief Newsletter

Stay updated with the latest news stories, along with original features, podcasts, videos, and more.