started · updated
Trezor data breach expands to 80,000 customers via shipping partner
Hardware wallet manufacturer Trezor has announced that a data breach involving its third-party shipping partner, ShipMonk, is significantly larger than initially reported. The total number of affected customers has risen to approximately 80,000 to 81,000, primarily in the United States.
The breach exposed sensitive personal information, including names, email addresses, phone numbers, shipping addresses, and order numbers. The compromised data includes records from orders placed between November 2019 and August 2021. Trezor expressed deep disappointment, noting that ShipMonk had provided repeated written assurances that customer data had been deleted in accordance with their 90-day retention policy, yet the records remained in the provider's systems.
Trezor emphasized that its own internal systems, hardware wallets, private keys, and customer funds were not compromised. However, the company warned that the leaked contact and address information increases the risk of highly targeted phishing attacks, social engineering, and potential physical security threats.
In response, Trezor plans to implement an 'Anonymous Delivery' feature in the EU by September 2026 and in the US by the end of the year to enhance user privacy and mitigate future risks.
Entities
Pocket Bitcoin · SatoshiLabs · ShipMonk · Trezor · United States
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 9 SOURCES] The breach included names, email addresses, phone numbers, shipping addresses, and order numbers. bittimes.net · bitcoinethereumnews.com · blockchainreporter.net · www.cryptobreaking.com · finbold.com · +3 more
- [● 9 SOURCES] The data breach at shipping partner ShipMonk affects approximately 80,000 to 81,000 customers in total. bittimes.net · bitcoinethereumnews.com · blockchainreporter.net · www.cryptobreaking.com · finbold.com · +3 more
- [● 7 SOURCES] Trezor's own systems, hardware wallets, private keys, and customer funds were not compromised. bittimes.net · bitcoinethereumnews.com · www.cryptobreaking.com · finbold.com · www.fortunegreece.com · +2 more
- [○ 1 SOURCE] Trezor plans to introduce 'Anonymous Delivery' features in the EU and US to mitigate future privacy risks. bittimes.net
- [● 8 SOURCES] ShipMonk failed to delete customer data despite receiving repeated written requests and assurances from Trezor. bittimes.net · bitcoinethereumnews.com · blockchainreporter.net · www.cryptobreaking.com · finbold.com · +2 more
- [● 8 SOURCES] The leaked data involved orders placed between November 2019 and August 2021. bittimes.net · bitcoinethereumnews.com · blockchainreporter.net · www.cryptobreaking.com · finbold.com · +2 more