Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S.
By Dillip Chowdary โข Sep 07, 2026 โข Source: BleepingComputer
What broke in Trezor data breach impact now reaches 81,000
80 words):* The long-term security implications for the affected customers also remain to be seen as phishing campaigns leverage this stolen information. While the hardware wallet manufacturer has notified the impacted individuals, the potential for targeted social engineering attacks persists indefinitely. There is also no public confirmation regarding whether the manufacturer will continue its relationship with this specific logistics provider or implement new data handling frameworks to prevent future incidents. Until these details are clarified, both
Trezor data breach impact now reaches 81,000 customers By Sergiu Gatlan September 7, 2026 08:16 AM 0 Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. In total, the breach has affected 81,000 customers after Trezor initially disclosed on August 13 that attackers accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers.
Who is exposed by Trezor data breach impact now reaches 81,000

As the company explained at the time, the incident also affected customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026. On Friday, it published an update to confirm that the breach impact has expanded after ShipMonk failed to delete the exposed data from its systems as required by Trezor's contract and data policy.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
What to do now about Trezor data breach impact now reaches 81,000
"Another 67,000 customers from the US who ordered between November 2019 and August 2021 were affected, with their full details (name, email, phone number, shipping address, order number) exposed," Trezor said. See the full write-up from BleepingComputer via the source link for quotes and complete context.
"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications. We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems." The company added that the breach did not affect its operations or services, that its systems were not compromised, and that all Trezor devices are secure.
How the Trezor data breach impact now reaches 81,000 issue works
It also warned affected customers to be wary of any messages requesting personal information, as they may be targeted in phishing attacks. The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks," Trezor said.
What is still unknown about Trezor data breach impact now reaches 81,000
As BleepingComputer previously reported, Metabase revealed that the threat actors exploited a critical SQL injection zero-day vulnerability to breach customer instances and carry out data theft attacks after gaining administrator access to the compromised instance. See the full write-up from BleepingComputer via the source link for quotes and complete context.
Developer Action Items
- โ Inventory whether Trezor data breach impact runs in prod, CI, staging, or on laptops before you debate severity.
- โ Confirm the vendor's fixed build for Trezor data breach impact from BleepingComputer, then schedule the patch window.
- โ If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
- โ Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
- โ Treat unexpected emails that mention Trezor data breach impact (shipping, invoices, password resets) as phishing until verified.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Advertisement