Trezor says ShipMonk breach exposed 67,000 more US users, taking total above 80,000

Trezor says ShipMonk breach exposed 67,000 more US users, taking total above 80,000

N
News Editor
2026-09-04 13:35:39
Trezor said a data breach tied to its mailing partner ShipMonk was far larger than first disclosed, with another roughly 67,000 US users now identified as affected. That pushes the total number of impacted users to more than 80,000. The hardware wallet maker had previously said 13,689 customers were exposed after attackers infiltrated ShipMonk’s systems, and at the time pointed to a 90-day data retention policy as a factor that limited the scope. Trezor now says that policy was never actually enforced and the data was never deleted. The company said it had repeatedly requested and received written confirmation from ShipMonk that deletions had taken place in line with contractual terms and internal policy. Trezor told Protos it is still too early to say how it will respond to ShipMonk’s conduct, but said it is arranging an additional audit of the mailing partner. The company also said it is working to introduce anonymous delivery as soon as possible so customers can better protect personal information when placing orders.

Trezor said a breach at mailing partner ShipMonk affected another roughly 67,000 US users, expanding the incident well beyond what the hardware wallet maker first disclosed last month. The new figure brings the total number of affected users to more than 80,000.

Last month, Trezor said personal details belonging to 13,689 customers had been exposed after bad actors infiltrated ShipMonk’s systems. At the time, the company said a 90-day data policy followed by its partners meant older user data had been deleted, which it presented as a factor that helped limit the leak.

Trezor now says that policy was never enforced and that the data was never deleted.

Trezor says it repeatedly sought confirmation that data had been deleted

In a statement, Trezor said, 「Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications.」

The company added, 「We’re terribly sorry to everyone affected. We take this matter very seriously and are working to ship anonymous delivery ASAP, so you can protect your personal information when placing an order.」

Trezor said leaks like this can give criminals more information to tailor attacks against crypto users.

Initial notice covered only orders from the previous 90 days

Trezor told Protos it is too early to decide what action it will take in response to ShipMonk’s conduct. It also said it is working to arrange an additional audit of the mailing partner.

According to Trezor, ShipMonk first alerted the company on August 10 to a breach affecting orders from the prior 90 days. On September 2, ShipMonk then told Trezor the exposure in fact stretched back to 2019 and 2021.

Trezor said, 「Our understanding is that our cooperation from those years was overlooked when the original scope was established.」

Trezor says it had no reason to expect a broader leak

When Protos asked why it was ShipMonk that disclosed the additional scope, Trezor said it had no reason to expect further leaks because ShipMonk had repeatedly provided assurances.

Protos also noted that Trezor contacted the outlet last month to reveal details of the original leak, but did not do so this time. Asked why, Trezor said, 「The information is public and it is not behind anything. Our priority was reaching the people actually affected.」

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.