< Back to all clusters
[TECHNOLOGY] · United States, United Kingdom, Czechia, Sweden, Colombia · 12 sources

started · updated

Trezor data breach expands to 80,000 customers via shipping partner

Hardware wallet manufacturer Trezor has announced that a data breach involving its third-party shipping partner, ShipMonk, is significantly larger than initially reported. The total number of affected customers has risen to approximately 80,000 to 81,000, primarily in the United States.

The breach exposed sensitive personal information, including names, email addresses, phone numbers, shipping addresses, and order numbers. The compromised data includes records from orders placed between November 2019 and August 2021. Trezor expressed deep disappointment, noting that ShipMonk had provided repeated written assurances that customer data had been deleted in accordance with their 90-day retention policy, yet the records remained in the provider's systems.

Trezor emphasized that its own internal systems, hardware wallets, private keys, and customer funds were not compromised. However, the company warned that the leaked contact and address information increases the risk of highly targeted phishing attacks, social engineering, and potential physical security threats.

In response, Trezor plans to implement an 'Anonymous Delivery' feature in the EU by September 2026 and in the US by the end of the year to enhance user privacy and mitigate future risks.

Entities

Pocket Bitcoin · SatoshiLabs · ShipMonk · Trezor · United States

Claims

What the coverage asserts, and how many sources carry each claim.