Trezor Discovers Broader Impact of Shipping Breach, Affecting Thousands More Customers
Trezor, a leading manufacturer of cryptocurrency wallets, has announced a significant expansion in the number of customers affected by a recent data breach involving one of its key shipping partners. In a detailed update released on September 4, the company revealed that the breach, which originated from its logistics partner ShipMonk, has compromised the data of 67,000 additional customers, bringing the total number of affected individuals to an alarming level.
Initially, Trezor notified the public of the breach on August 13, estimating that the compromised data was limited to a time frame between May 10 and August 8, 2026. This latest announcement, however, indicates that data from an extensive period—ranging from November 2019 to August 2021—was also included in the breach. This shocking revelation marks a staggering 479% increase in the victim count, underscoring the severity of the incident and the risk it poses to Trezor customers.
The scope of the data breach is troubling, as it involved the exposure of full customer details. This includes names, email addresses, phone numbers, shipping addresses, and order numbers, putting those affected at risk for potential scams. Trezor has issued warnings, advising customers to remain vigilant against the increased possibility of phishing attempts. The leaked information could be exploited by malicious actors for fraudulent emails, calls, or even physical threats, making it imperative for users to monitor their accounts closely.
In the realm of cybersecurity, Trezor customers have become a prime target for threat actors over the past few years. A notable incident occurred in 2022 when the company was compelled to clarify that an email sent to customers about a purported major data breach was, in fact, a scam aimed at tricking individuals into sharing their wallet recovery codes. This history highlights the vulnerabilities faced by Trezor’s user base and amplifies concerns regarding the latest breach.
Fallout from the Supply Chain Incident
At the heart of the issue lies a supply chain failure attributed to Trezor’s logistics partner, ShipMonk. In its public communications, Trezor laid blame at ShipMonk’s feet, stating that the partner did not adhere to the data minimization policy mandated by their agreement. The crypto wallet manufacturer expressed disappointment in ShipMonk’s failure to delete the data, despite receiving written assurances to that effect throughout their partnership.
Trezor’s communication on platforms like X (formerly known as Twitter) emphasized its commitment to data protection, stating, "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications.” This statement indicates not only the frustration felt by Trezor but also the impact of trust when it comes to data handling in the supply chain.
Following the breach, Trezor is currently deliberating on the possibility of legal action against ShipMonk. The company is in ongoing discussions with ShipMonk to ascertain the exact nature of the breach and the data that was compromised. Trezor reported that ShipMonk had taken measures to secure the affected systems and enhance their security protocols post-incident.
Additionally, Trezor has outlined plans to expedite the implementation of anonymous delivery options in their online shop. This strategic move aims to minimize the amount of personal information exchanged in future transactions, thereby reducing the risks associated with such breaches. Customers are encouraged to limit the data they share by using alternative methods for receiving their orders, such as PO boxes, parcel lockers, or designated pickup points.
As Trezor navigates the ramifications of this significant breach, the crypto community is left to ponder the implications for data privacy and security in the cryptocurrency space. This incident serves as a stark reminder of the importance of robust security measures throughout the supply chain and the need for vigilance among users in protecting their digital assets.

