Free News Reader

Trezor Data Breach Affects Additional 67,000 US Customers

Free News Reader  ·  September 5, 2026

AI-generated context summary requested by a Free News Reader user. Sourced via Gemini from publicly available information — no paywalled content was accessed.

You hit a paywall. Here’s the context on this topic based on publicly available information. We did not access any paywalled content. View original article.

Trezor Data Breach Affects Additional 67,000 US Customers

  • An additional 67,000 US customers of the crypto hardware wallet company Trezor have had their personal data exposed in a breach at its shipping provider, ShipMonk, bringing the total number of affected individuals to roughly 80,000.
  • The newly discovered exposed data includes customer names, email addresses, phone numbers, shipping addresses, and order numbers from purchases made between November 2019 and August 2021.

Full Summary — powered by AI

Crypto hardware wallet manufacturer Trezor announced on September 4, 2026, that a data breach at its third-party shipping provider, ShipMonk, exposed the personal information of an additional 67,000 US customers. This new disclosure significantly expands an incident initially reported in August, which affected 13,689 customers across various countries. The total number of impacted individuals is now estimated to be around 80,000.

The exposed data from this latest revelation includes customer names, email addresses, phone numbers, shipping addresses, and order numbers for purchases made between November 2019 and August 2021. Trezor expressed disappointment, stating that they had repeatedly requested and received written assurances from ShipMonk that this older data had been deleted, in line with their contract and data retention policies.

Trezor emphasized that its own systems, products, and hardware wallets were not compromised in the breach, meaning users’ recovery seeds, private keys, or wallet funds remain secure. However, the company warned that the leaked contact and order information could be used by malicious actors for more convincing phishing attacks, fraudulent calls or letters, and potentially even physical targeting.

The initial breach at ShipMonk was reported to Trezor on August 10, 2026, and was attributed to unauthorized access to ShipMonk’s systems. This unauthorized access exploited a critical SQL injection flaw in Metabase, an analytics platform used by ShipMonk. Trezor has directly notified all affected customers. In response to such incidents, Trezor is promoting an “Anonymous Delivery” system to reduce the amount of customer information retained during hardware wallet purchases, with a US rollout planned by the end of 2026.