Published: September 5, 2026
Last fact-checked: September 5, 2026
Current status: Trezor says the ShipMonk data breach now includes approximately 67,000 additional U.S. customers whose older order records were exposed.
The Trezor data breach has expanded well beyond the group disclosed in August. On September 4, Trezor said ShipMonk informed it that approximately 67,000 additional U.S. customers were affected. The newly identified records relate to orders from November 2019 through August 2021 and include names, email addresses, phone numbers, shipping addresses and order numbers. Trezor says its own systems and hardware wallets were not compromised. Customers who received a breach notice should treat unexpected wallet-related emails, calls and letters as higher-risk and verify communications independently.
Key Facts
- Trezor updated its breach notice on September 4, 2026.
- Approximately 67,000 additional U.S. customers are affected.
- The new group ordered between November 2019 and August 2021.
- Exposed fields include name, email, phone number, shipping address and order number.
- Trezor says affected customers were emailed directly and its devices remain secure.
- No compensation, refund or claims program has been announced in Trezor’s notice.
What Changed in the Trezor Data Breach
Trezor first disclosed the ShipMonk incident on August 13. At that point, it reported 11,742 customers with full exposure and 1,947 with partial exposure. The company initially described the incident as largely limited by a 90-day data-retention policy.
That picture changed on September 4. In its updated security notice, Trezor said ShipMonk had informed it on September 2 that older order data from the companies’ prior cooperation remained in the breached systems. Trezor says it had repeatedly received written assurances that the information had been deleted.
| Disclosure | Customers described | Order period | Data described |
|---|---|---|---|
| August 13 disclosure | 11,742 full exposure; 1,947 partial | Primarily recent 2026 orders; Trezor later said some partial records were older | Full group: name, email, phone and shipping address; partial group: more limited identity/contact data |
| September 4 update | About 67,000 additional U.S. customers | November 2019-August 2021 | Name, email, phone, shipping address and order number |
Illustrative arithmetic: 13,689 originally disclosed customers plus approximately 67,000 additional customers equals roughly 80,689 affected customer records based on Trezor’s published figures. Because the newer figure is approximate, this calculation should not be treated as a final audited total.
What Was Not Reported as Compromised
Trezor says the incident occurred at ShipMonk, not within Trezor’s own systems, products or services. Its notice says Trezor devices remain secure. The exposed fields listed for the newly identified U.S. group are shipping and contact records; Trezor does not list wallet backups or private keys among the exposed data.
That distinction matters. The disclosure does not establish that cryptocurrency was stolen, that every affected customer experienced identity theft, or that an attacker gained access to a Trezor wallet. It also does not establish a consumer payment or reimbursement right.
Why the Exposed Address and Order Data Matter
The immediate risk described by Trezor is targeted social engineering. A scammer who knows a person’s name, phone number, address and that the person placed a Trezor order can make a fake security warning appear more credible.
Trezor specifically warns about scam emails, fraudulent calls or letters and possible physical-security risks. It tells users never to share a wallet backup or enter it on a website.
What Affected U.S. Customers Can Do
- Confirm the notice independently. Do not use a link or phone number from an unexpected follow-up message. Open Trezor’s known website directly and compare the communication with its official breach notice.
- Never disclose the wallet backup. A message that knows your address or order details is not proof that the sender is Trezor.
- Preserve the breach email. Keep the notice, date received and any later suspicious emails, texts, calls or letters.
- Watch for identity misuse. The FTC’s data-breach recovery guidance explains how to check, freeze and monitor credit when appropriate and what to do if personal information is misused.
- Report actual identity theft. IdentityTheft.gov can generate an FTC Identity Theft Report and a recovery plan.
- Report phishing. The FTC’s phishing guidance recommends avoiding unexpected links and contacting the company through a website or number you already know is legitimate.
Records Worth Keeping
- Trezor’s breach-notification email;
- the original order confirmation, if still available;
- screenshots and full headers of suspicious emails;
- phone numbers, voicemail and fraudulent letters;
- dates of any account-security changes; and
- reports or confirmation numbers if identity misuse occurs.
Do not publish a wallet backup, private key, full financial-account number or other sensitive credential when reporting a scam.
Technical Cause and Remaining Limitations
Metabase’s August 6 security advisory
Official Source Stack
Direct sources supporting the material claims in this report.
- Official agency release data-breach recovery guidance
- Official agency release IdentityTheft.gov
- Official agency release phishing guidance
This report provides general news and educational information for a U.S. audience. It is not individualized financial, credit, legal, tax, insurance or investment advice. Verify current procedures through the linked official sources.