EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Trezor ShipMonk data breach affects 67,000 U.S. users

2026-09-04 20:21:29
Bookmark

Trezor reveals that the scope of ShipMonk data breach expands

Trezor announced that it would expand its reporting scope of ShipMonk data breach after discovering that the personal information of approximately 67,000 U.S. customers had been compromised due to orders dating back to 2019. A newly confirmed customer base ordered Trezor equipment during this period, which spans from November 2019 to August 2021. The records affected include names, email addresses, telephone numbers, shipping addresses and order numbers, which significantly expanded the impact of the accident that was originally thought to be mainly limited to recent purchases.

The so-called "deleted" data retained by ShipMonk

This discovery directly conflicts with Trezor's customer data retention policy. Trezor pointed out that ShipMonk had provided multiple written assurances that it had deleted the earlier shipping information in accordance with contract requirements, Trezor's data policies, and previous communications between the parties. However, this is not the case.

Trezor first disclosed the ShipMonk data breach on August 13, when he learned that an unauthorized entity had accessed customer information held by a logistics service provider. Preliminary investigations determined that 11,742 customers 'names, emails, telephone numbers and shipping addresses were leaked, and some information of another 1,947 customers was affected. At the time, the industry generally believed that the 90-day data deletion requirement would limit the scope of disclosure to recent orders. But newly discovered records from 2019 to 2021 show that despite this requirement, ShipMonk retains a large amount of older customer information in its systems.

Trezor emphasized that its system, firmware, private key and wallet backup were not compromised. The leak occurred inside ShipMonk's compliance infrastructure, not the hardware wallet itself.

Transportation data raises targeted phishing risk

Names, phone numbers and physical shipping addresses are enough for attackers to build highly personalized phishing attempts, specifically targeting known hardware wallet users. Victims may receive fraudulent emails, phone calls or physical letters posing as Trezor, exchanges, banks or delivery companies.

Trezor instructs customers not to disclose or enter wallet backup information for any communication that claims that a device, account, or mnemonic requires urgent verification. Previously, Trezor has also dealt with third-party exposures. An independent incident in December 2025 involved suspicious activity related to external services, but did not result in any database, device or wallet software damage at the time.

Anonymous delivery plans gain urgency

Trezor is developing an "anonymous delivery" option that aims to reduce the personally identifiable information associated with hardware wallet purchases. Planned features include locker pickup, neutral packaging, universal sender information and automatic deletion of shipping identifiers after delivery. The service was originally scheduled to be launched in Europe in September 2026 and rolled out in the United States before the end of the year.

As the historical record of the newly discovered discovery becomes public, the scope of the ShipMonk leak has increased significantly from the original 13,689 customers. Currently, approximately 67,000 U.S. buyers from November 2019 to August 2021 are being notified of this.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP