EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Trezor blames ShipMonk for data breach affecting users soaring to 80,700 U.S. users

2026-09-05 00:18:26
Bookmark

Trezor's data breach expands: The number of affected users has increased to 80,700

The latest announcement released on Friday showed that Trezor revealed that the data breach at its logistics partner ShipMonk was more serious than previously estimated. Specifically, the personal information of another 67,000 U.S. users was exposed, including names, addresses, phone numbers, email addresses and order data.

Currently, the total number of users who may be affected by the data breach has reached 80,700, which means that users holding Trezor hardware wallets are at potential risk.

Trezor pointed out in a post posted on platform X (formerly Twitter) that the newly leaked data involved orders placed by U.S. customers between November 2019 and August 2021. It is worth noting that some of the information is nearly seven years old. This time span is significant because as early as August this year, when Trezor first announced the data breach, the industry believed that the "90-day data deletion policy" implemented by its compliance partners had limited the number of affected users to a certain range.

Accountability and Data Verification

Trezor said that the company has repeatedly asked ShipMonk to provide documentary proof confirming that it has deleted old order data for more than 90 days. Each request received a positive answer. However, Trezor expressed disappointment that the documents ultimately proved to be inaccurate. Trezo reportedly clearly blamed the logistics provider, accusing it of violating its promise to retain data that should have been deleted.

The amount of new data far exceeds previous estimates. In August, Trezor estimated that the leak involved about 14,000 people. But two days before Friday's disclosure, ShipMonk informed Trezor of the results of the survey, raising the total number of affected users to about 80,700.

Two days ago, we received the latest update from logistics service provider ShipMonk. We are deeply saddened to inform you that recent data breaches have affected more customers than originally thought. Another 67,000 U.S. customers who placed orders between November 2019 and August 2021 were affected...

- Trezor (@Trezor) September 4, 2026

System security has not been compromised, but privacy risks have increased

Trezor clarified that its internal systems have not been compromised and no device, private key or wallet backup has been compromised. Because this leak occurred purely in the logistics process. What is mainly affected are customer contact information and delivery information.

How mailing lists become attack weapons

The core danger of this incident lies in "precise targeting." The leaked mailing list contains verification information for hardware wallet owners, including the addresses where cryptocurrency users live, allowing hackers to launch phishing attacks against these specific groups of people, ranging from emails, phone calls and even traditional postal letters.

Trezo advised affected users to be vigilant about such attempts and highlighted potential personal safety risks.

This threat is real. In February, some users of Trezor and Ledger wallets received forged letters. The letters were printed with holograms, QR codes and even mimicked executives 'signatures, urging users to conduct fake security tests or their accounts would be locked.

Cybersecurity expert David Sehyeon Baek pointed out that when forged letters come with their real names and addresses, it changes the victim's psychological state and makes it easier for them to believe the scam.

The severity of the phishing problem

Impersonation scams do not necessarily require the use of technical loopholes to steal assets from users 'wallets. In fact, such fraud has become one of the main reasons for cryptocurrency losses.

Blockchain cybersecurity company Hacken found that of the total $482 million stolen in the first quarter, phishing and social engineering scams accounted for as much as $306 million. In July alone, an investor narrowly missed losing $1 million after confirming malicious token transactions on Ethereum.

In addition, this is not the first time Trezor has faced breaches involving leaks of user contact details. In January 2024, the company disclosed that approximately 66,000 customers who had contacted its support team since December 2021 had suffered phishing scams.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP