Cryptocurrency hardware wallet manufacturer Trezor has confirmed that a data breach at its shipping partner, ShipMonk, has impacted a significantly larger number of customers than initially reported. The company now states that 81,000 customers have been affected, a 479% increase from the original estimate of 14,000.
The breach, which Trezor first disclosed on August 13, 2026, was initially believed to have compromised order data from May 10 to August 8, 2026. However, an update on September 4, 2026, revealed that the stolen data trove also included order information spanning from November 2019 to August 2021.
The exposed information includes sensitive customer details such as names, email addresses, phone numbers, shipping addresses, and order numbers. Trezor has warned affected individuals of an increased risk of phishing attacks, fraudulent calls, and letters, and has also cautioned about potential physical security risks due to the leaked data.
Trezor has attributed the incident to ShipMonk, stating that the logistics partner failed to adhere to its data minimization policy. The company claims it had repeatedly requested and received written assurances from ShipMonk confirming the deletion of data in line with their contract and data policy. Trezor expressed disappointment that, despite these confirmations, the data was not deleted from ShipMonk's systems.
ShipMonk has reportedly secured the affected systems and enhanced its security measures following the incident. Trezor is currently in direct communication with ShipMonk to ascertain the exact details of the breach and is evaluating potential legal action.
In response to the breach, Trezor is accelerating efforts to implement anonymous delivery options in its online store to reduce the amount of personal data that needs to leave its systems. In the interim, customers are advised to minimize shared information by utilizing PO boxes, parcel lockers, or pickup points for deliveries.
This incident is not the first time Trezor customers have been targeted by threat actors. In 2022, the company had to issue a clarification regarding a scam email that falsely warned of a data breach, attempting to trick users into divulging their wallet recovery codes.






