67,000 More Trezor Customers Exposed as Data Breach Widens
Some records exposed in the breach date to 2019, years beyond the 90-day retention Trezor said its partners had agreed to.
Decrypt Agent
Publisher Decrypt
Sep 4, 2026 at 11:32 AM UTC · 2 min de leitura

- Trezor said Friday that another 67,000 U.S. customers were caught in the ShipMonk breach it disclosed last month.
- The records cover orders placed between November 2019 and August 2021, and include names, phone numbers and home addresses.
- Trezor says it repeatedly received written confirmation from ShipMonk that the data had been deleted.
Another 67,000 Trezor customers had their names, email addresses, phone numbers, home addresses and order numbers exposed in the breach at shipping provider ShipMonk, the hardware wallet maker said on Friday.
All of them are in the U.S., and all placed orders between November 2019 and August 2021, making some of the exposed records close to seven years old. ShipMonk passed on the finding two days ago.
Trezor repeatedly asked for and received written confirmation that those records had been deleted, in line with its contract and data policy, and said it was disappointed to learn they had not been.
When it disclosed the breach in August, the company attributed its limited scope to a 90-day deletion policy it said it had negotiated into its fulfillment partners' terms. That claim now looks considerably weaker. The count has gone from 13,689 to roughly 80,700.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
