Skip to content
Independent consumer-finance journalism
Fiscal Wire News Facts for your financial life
Scams & Fraud

Trezor Data Breach Expands: 67,000 More U.S. Customers Exposed

Published: September 5, 2026 Last fact-checked: September 5, 2026 Current status: Trezor says the ShipMonk data breach now includes approximately 67,000 additional U.S. customers whose older order records were exposed. The Trezor data breach has expanded well beyond the group disclosed in…

Verified Wire

Verification details

Last fact-checkedSeptember 5, 2026

Hardware wallet beside a shipping package with redacted address labels and a digital security warning
Trezor says approximately 67,000 additional U.S. customers were exposed through the ShipMonk data breach.

Published: September 5, 2026

Last fact-checked: September 5, 2026

Current status: Trezor says the ShipMonk data breach now includes approximately 67,000 additional U.S. customers whose older order records were exposed.

The Trezor data breach has expanded well beyond the group disclosed in August. On September 4, Trezor said ShipMonk informed it that approximately 67,000 additional U.S. customers were affected. The newly identified records relate to orders from November 2019 through August 2021 and include names, email addresses, phone numbers, shipping addresses and order numbers. Trezor says its own systems and hardware wallets were not compromised. Customers who received a breach notice should treat unexpected wallet-related emails, calls and letters as higher-risk and verify communications independently.

Key Facts

  • Trezor updated its breach notice on September 4, 2026.
  • Approximately 67,000 additional U.S. customers are affected.
  • The new group ordered between November 2019 and August 2021.
  • Exposed fields include name, email, phone number, shipping address and order number.
  • Trezor says affected customers were emailed directly and its devices remain secure.
  • No compensation, refund or claims program has been announced in Trezor’s notice.

What Changed in the Trezor Data Breach

Trezor first disclosed the ShipMonk incident on August 13. At that point, it reported 11,742 customers with full exposure and 1,947 with partial exposure. The company initially described the incident as largely limited by a 90-day data-retention policy.

That picture changed on September 4. In its updated security notice, Trezor said ShipMonk had informed it on September 2 that older order data from the companies’ prior cooperation remained in the breached systems. Trezor says it had repeatedly received written assurances that the information had been deleted.

Trezor’s disclosed breach scope before and after the September 4 update
Disclosure Customers described Order period Data described
August 13 disclosure 11,742 full exposure; 1,947 partial Primarily recent 2026 orders; Trezor later said some partial records were older Full group: name, email, phone and shipping address; partial group: more limited identity/contact data
September 4 update About 67,000 additional U.S. customers November 2019-August 2021 Name, email, phone, shipping address and order number

Illustrative arithmetic: 13,689 originally disclosed customers plus approximately 67,000 additional customers equals roughly 80,689 affected customer records based on Trezor’s published figures. Because the newer figure is approximate, this calculation should not be treated as a final audited total.

What Was Not Reported as Compromised

Trezor says the incident occurred at ShipMonk, not within Trezor’s own systems, products or services. Its notice says Trezor devices remain secure. The exposed fields listed for the newly identified U.S. group are shipping and contact records; Trezor does not list wallet backups or private keys among the exposed data.

That distinction matters. The disclosure does not establish that cryptocurrency was stolen, that every affected customer experienced identity theft, or that an attacker gained access to a Trezor wallet. It also does not establish a consumer payment or reimbursement right.

Why the Exposed Address and Order Data Matter

The immediate risk described by Trezor is targeted social engineering. A scammer who knows a person’s name, phone number, address and that the person placed a Trezor order can make a fake security warning appear more credible.

Trezor specifically warns about scam emails, fraudulent calls or letters and possible physical-security risks. It tells users never to share a wallet backup or enter it on a website.

What Affected U.S. Customers Can Do

  1. Confirm the notice independently. Do not use a link or phone number from an unexpected follow-up message. Open Trezor’s known website directly and compare the communication with its official breach notice.
  2. Never disclose the wallet backup. A message that knows your address or order details is not proof that the sender is Trezor.
  3. Preserve the breach email. Keep the notice, date received and any later suspicious emails, texts, calls or letters.
  4. Watch for identity misuse. The FTC’s data-breach recovery guidance explains how to check, freeze and monitor credit when appropriate and what to do if personal information is misused.
  5. Report actual identity theft. IdentityTheft.gov can generate an FTC Identity Theft Report and a recovery plan.
  6. Report phishing. The FTC’s phishing guidance recommends avoiding unexpected links and contacting the company through a website or number you already know is legitimate.

Records Worth Keeping

  • Trezor’s breach-notification email;
  • the original order confirmation, if still available;
  • screenshots and full headers of suspicious emails;
  • phone numbers, voicemail and fraudulent letters;
  • dates of any account-security changes; and
  • reports or confirmation numbers if identity misuse occurs.

Do not publish a wallet backup, private key, full financial-account number or other sensitive credential when reporting a scam.

Technical Cause and Remaining Limitations

Metabase’s August 6 security advisory

Primary evidence

Official Source Stack

Direct sources supporting the material claims in this report.

  1. Official agency release data-breach recovery guidance
  2. Official agency release IdentityTheft.gov
  3. Official agency release phishing guidance
Publisher & reviewer

Shailendra Singh

Fiscal Wire News publishes independent, evidence-first reporting focused on U.S. consumer finance and financial rights.

About the publisher →

This report provides general news and educational information for a U.S. audience. It is not individualized financial, credit, legal, tax, insurance or investment advice. Verify current procedures through the linked official sources.