Trezor data breach impact now reaches 81,000 customers

A Cryptocurrency Hardware Wallet Maker’s Data Breach Expands to Affect Over 81,000 Customers

Cryptocurrency hardware wallet maker Trezor has announced that a recent data breach at its shipping and logistics provider, ShipMonk, has expanded to affect an additional 67,000 US customers. This brings the total number of affected customers to over 81,000.

The initial breach was disclosed on August 13, when Trezor revealed that attackers had accessed the data of nearly 14,000 customers, including their full names, shipping addresses, email addresses, and phone numbers. The incident also affected customers in several other countries who received orders between May 10 and August 8, 2026.

It appears that ShipMonk, despite repeated requests from Trezor to delete the exposed data from its systems, failed to do so as required by their contract and data policy. This oversight has resulted in a much larger number of customers being affected than initially thought. “Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data,” Trezor stated. “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”

Trezor has assured its customers that its own operations and services have not been compromised, and that all Trezor devices remain secure. However, affected customers should be aware of an increased risk of phishing attacks, as the leaked information could be used by scammers to target them.

The breach is linked to a Metabase campaign, which exploited a critical SQL injection zero-day vulnerability in the third-party analytics platform. This vulnerability allowed attackers to gain administrator access to compromised instances and carry out data theft attacks. ShipMonk has reportedly received extortion emails from the ShinyHunters extortion gang, adding to the severity of the situation.

This is not the first time Trezor has faced a data breach. In January 2024, the company disclosed another breach after threat actors compromised its third-party support ticketing portal and accessed data from roughly 66,000 users. The stolen data was later used in phishing attacks attempting to steal recipients’ 24-word wallet recovery seeds.

The recent expansion of the ShipMonk breach highlights the importance of robust security measures for companies that handle sensitive customer data. It also underscores the need for vendors to prioritize data protection and ensure that their third-party providers are meeting security standards.

As a result of this incident, Trezor is advising affected customers to be cautious of any messages requesting personal information. “Be aware of the increased risk of phishing,” the company warned. “The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks.”


Source: Bleeping Computer — 2026-09-07