Trezor says breach was larger than first disclosed, with another 67,000 U.S. customers exposed

Trezor says breach was larger than first disclosed, with another 67,000 U.S. customers exposed

N
News Editor
2026-09-04 20:30:14
Hardware wallet maker Trezor said the customer data breach it disclosed last month was more extensive than it first reported. On Friday, the Prague-based company said another 67,000 U.S. customers were affected, with leaked records including names, email addresses, phone numbers, shipping addresses and order numbers tied to purchases made between November 2019 and August 2021. Trezor also said another 1,947 customers had their names, cities and email addresses exposed. The company said its third-party fulfillment partner, ShipMonk, had falsely assured Trezor in writing that customer data had been deleted from its systems. Trezor said it had repeatedly sought confirmation that the data was erased in line with contractual terms and its data policy, but the information remained in ShipMonk’s systems. The company had previously disclosed in August that 11,742 customers across the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal were affected after unauthorized access hit ShipMonk’s systems. Trezor said it had emailed all impacted customers directly. Parent company SatoshiLabs told Bitcoin Magazine last month that it was investigating the incident. The report also pointed to prior breaches in the hardware wallet sector, including Ledger’s 2020 database leak and customer notices earlier this year tied to Ledger payment partner Global-e.

Trezor said the data breach it disclosed last month was more severe than first reported, with another 67,000 U.S. customers now confirmed as affected.

Trezor says breach was larger than first disclosed, with another 67,000 U.S. customers exposed 2

The Prague, Czech Republic-based hardware wallet maker said Friday that the newly identified exposure included customers’ names, email addresses, phone numbers, shipping addresses and order numbers. According to Trezor, the leaked records came from orders placed between November 2019 and August 2021.

Trezor expands the scope of affected users

Trezor had first announced in August that data tied to 11,742 customers in the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal had been exposed. In that earlier disclosure, the company said the leaked information included names, email addresses, phone numbers and shipping addresses.

In its latest update, Trezor wrote: 「Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021…」

Trezor also said another 1,947 customers had their names, cities and email addresses exposed in the breach.

Trezor says ShipMonk failed to delete customer data

In Friday’s announcement, the company said its third-party fulfillment partner, ShipMonk, had falsely reassured Trezor that customer data had been deleted.

Trezor wrote: 「Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications.」 The company added: 「We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.」

Neither Trezor nor ShipMonk immediately responded to questions from Bitcoin Magazine.

Incident was first disclosed in August

When Trezor first revealed the breach in August, it said ShipMonk had experienced unauthorized access to systems containing customer data. The company also said it had directly emailed all customers involved in the incident.

Trezor’s parent company, SatoshiLabs, told Bitcoin Magazine last month that it was investigating the matter.

Hardware wallet users have faced similar incidents before

Trezor is one of the best-known Bitcoin hardware wallet providers and also supports storage for other cryptocurrencies.

The report noted that Bitcoin users’ personal data has been targeted before. In 2020, an unauthorized party accessed hardware wallet maker Ledger’s e-commerce and marketing database, exposing more than 1 million email addresses and the personal contact data of nearly 10,000 customers.

Earlier this year, customers also reported receiving emails from Global-e, Ledger’s payment partner, saying that a breach in its cloud systems had exposed sensitive customer data.

The story was first published by Bitcoin Magazine and written by Mathew Di Salvo.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.