Trezor Data Breach Grows Nearly Fivefold to 81,000 Affected Customers
Cryptocurrency hardware wallet maker Trezor has significantly increased its breach estimate, revealing that a security incident at its shipping partner ShipMonk exposed data belonging to 81,000 customers, far more than the original figure disclosed in August. The company initially believed only orders from May to August 2026 were affected, but has since confirmed that stolen data spans back to November 2019.
The exposed information includes customer names, email addresses, phone numbers, shipping addresses and order numbers. Trezor has warned customers to be alert for phishing emails, fraudulent phone calls, fake letters and other scams that could exploit this data, noting the leak could also create physical security risks for individuals whose addresses were exposed.
Trezor says it had repeatedly received written assurances from ShipMonk that customer data would be deleted in line with contractual obligations, but this did not happen. The company is considering legal action and is working to reduce future exposure by developing anonymous delivery options, while advising customers in the meantime to use PO boxes, parcel lockers or pickup points to limit the personal information shared with third parties.