Newsroom
4 September, 2026 / News / AI / Tags: trezor, shipmonk, customers, breach, shipping

Hardware wallet maker reports older order records from 2019-2021 remained in systems despite deletion assurances, raising total affected above 80,000
Hardware wallet manufacturer Trezor disclosed on Friday that a data breach at its shipping partner ShipMonk exposed personal information of approximately 67,000 additional US customers, far exceeding the scale first reported last month.
The newly identified records belong to customers who placed orders between November 2019 and August 2021. Exposed details include full names, email addresses, phone numbers, shipping addresses and order numbers. Some of the data is nearly seven years old.
Trezor first announced the incident in mid-August after ShipMonk reported unauthorized access to systems holding customer order data. At that time the company stated that 13,689 customers were affected. Of those, 11,742 experienced full exposure of names, emails, phone numbers and shipping addresses, while 1,947 had more limited information compromised, consisting of names, cities and email addresses.
Those earlier records related to orders shipped between May 10 and August 8 2026 to customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor had attributed the relatively contained impact to a 90-day data retention policy that its fulfillment partners were required to follow.
On September 2 ShipMonk informed Trezor that the breach also encompassed order data from an earlier period of cooperation. The additional US records push the total number of known affected customers above 80,000.
Trezor stated that throughout its relationship with ShipMonk it repeatedly requested confirmation that older customer data had been deleted in line with contractual terms and its data policy. The company said it received written assurances that the deletion had taken place.
“We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems,” Trezor said in its update.
The company indicated it had no reason to anticipate further disclosures because of those repeated confirmations. Trezor is now arranging an additional audit of the shipping partner and has not yet decided on further actions.
Trezor stressed that its own systems were not compromised. Hardware wallets, private keys and wallet backups remain secure. The risk stems from the exposure of personal details that identify individuals as hardware wallet owners, potentially enabling more targeted phishing attempts, fraudulent emails, phone calls or physical letters.
The company has directly emailed all newly affected customers. Anyone who has not received a notification is not believed to be impacted by the expanded disclosure. Trezor also warned of possible physical security risks associated with the leaked home addresses.
Trezor said it is accelerating efforts to introduce anonymous delivery options that use neutral packaging, locker pickup and generic sender details so customers no longer need to provide home addresses for future orders.
The breach itself originated from a critical vulnerability in the analytics platform Metabase used by ShipMonk. The flaw allowed unauthorized access to connected databases before it was patched.









