cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/Trezor Breach Expands After ShipMonk Retained Old Customer Records

Trezor Breach Expands After ShipMonk Retained Old Customer Records

Van Thanh Le

Van Thanh Le

PublishedSep 4 2026

UpdatedSep 4 2026

1 hour ago3 minutes read
Trezor breach expands due to legacy data retained by ShipMonk

Historical order data widened exposure far beyond the initially identified customers

TL;DR

  • Trezor said another 67,000 U.S. customers were affected by the ShipMonk data breach, taking the known total above 80,000.
  • ShipMonk had retained older customer records despite written assurances to Trezor that the data had been deleted.
  • Trezor said its systems and customer wallet backups were unaffected, but exposed personal data could enable targeted scams and physical-security risks.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


Trezor said on September 4, 2026, that a data breach at shipping provider ShipMonk affected another 67,000 U.S. customers, dramatically expanding an incident first disclosed in August. Trezor said older customer records had remained on ShipMonk’s systems despite repeated assurances that they had been deleted, while Trezor’s own systems, customer wallet backups and customers’ cryptocurrency were not directly compromised.

tweet-2095807665603584085.webp

Trezor initially disclosed that 13,689 customers had been affected after malicious actors infiltrated ShipMonk’s systems. The original group included 11,742 customers whose names, contact details and shipping addresses were exposed, while 1,947 customers had a smaller set of information compromised. The newly identified group brought the known total to roughly 80,689 customers, while Trezor separately characterized the overall affected population as more than 80,000.

Affected group Customers Details
Original disclosure 13,689 Initial customers identified after the ShipMonk intrusion
Full personal-data exposure 11,742 Names, contact details and shipping addresses exposed
More limited exposure 1,947 Smaller set of personal details compromised
Newly identified U.S. customers 67,000 Historical ShipMonk records added to the breach scope
Known combined total About 80,689 Approximate total because the newest cohort was reported as a rounded figure

ShipMonk’s initial breach scope omitted older orders

ShipMonk first informed Trezor on August 10, 2026, that the breach covered orders from the previous 90 days, according to Trezor. ShipMonk then informed Trezor on September 2 that affected records extended back to customers who had placed orders between November 2019 and August 2021. The newly surfaced information included names, email addresses, phone numbers, shipping addresses and order numbers, with some of the records described as almost seven years old.

Trezor said it had expected historical customer information to have been removed under its data-retention practices. “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” Trezor said.

Trezor said the older period had not been included when ShipMonk established the incident’s original boundaries. “Our understanding is that our cooperation from those years was overlooked when the original scope was established,” Trezor said. Asked why it had not anticipated additional historical exposure, Trezor said it had “no reason to expect it” because of ShipMonk’s repeated deletion assurances.

Trezor said everyone identified in the expanded group had been contacted directly by email. The company also said it was too early to decide how it would respond to ShipMonk’s actions and was working to arrange an additional audit of the shipping partner.

Wallets remained secure as personal-data risks increased

Trezor said its own systems were unaffected, customer wallet backups were not exposed and the attacker did not gain direct access to customers’ cryptocurrency. The exposed personal data could nevertheless support more convincing impersonation and social-engineering attempts because attackers could possess a customer’s identity, contact information and evidence of a Trezor purchase.

Shipping-address exposure also creates a physical-security concern because those addresses may identify homes where hardware wallets are kept. Trezor advised customers never to reveal a wallet backup or enter it on a website regardless of who asks for it. Customers who did not receive a notification email are not currently believed to have been affected.

Trezor said it is now working to introduce anonymous delivery so buyers can share less personal information when ordering devices. “We’re terribly sorry to everyone affected. We take this matter very seriously and are working to ship anonymous delivery ASAP, so you can protect your personal information when placing an order,” Trezor said.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.14.17
© 2017 - 2026 COIN360.com. All Rights Reserved.