Skip to content
Trezor Supply Chain Breach Now Impacts 81,000 Customers

Trezor Supply Chain Breach Now Impacts 81,000 Customers

Infosecurity-Magazine September 8, 2026

Cryptocurrency wallet manufacturer Trezor has revealed that a breach at a key shipping partner has affected 67,000 more customers than originally thought.

In an update posted on September 4, the hardware specialist said it was informed that the trove stolen from ShipMonk also included order data from the time period November 2019 – August 2021.

When the original breach notification was posted on August 13, the firm claimed that only data from between May 10 and August 8 2026 was involved.

The new victim count represents a 479% increase on the original estimate.

Full details were exposed in the incident, including customer names, emails, phone numbers, shipping addresses and order numbers.

“Be aware of the increased risk of phishing,” the firm warned. “The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks.”

Trezor customers have been a popular target for threat actors over the years. In 2022, it was forced to clarify that an email sent to customers warning of a major data breach at the firm was a scam designed to trick them into handing over their wallet recovery codes.

Trezor laid the blame for the recent breach firmly at the feet of its logistics partner, claiming that its data minimization policy wasn’t followed.

“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” it wrote in a post on X (formerly Twitter). “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”

Trezor said it was still deciding whether to take legal action against the firm.

“We are in direct with ShipMonk to establish exactly what happened and which data was reached. ShipMonk has secured the affected systems and hardened its security after the incident,” it continued.

“We are also speeding up work on anonymous delivery in our shop, so that in the future less personal data has to leave our systems at all, and in the meantime you can already keep what you to a minimum by using a PO box, parcel locker, or pickup point.”

Nissan: Thousands Impacted By Red Hat Breach News 23 December 2025

Nissan: Thousands Impacted By Red Hat Breach

US Data Breaches Head for Another Record Year After 11% Surge News 17 July 2025

US Data Breaches Head for Another Record Year After 11% Surge

Dozens of Corporates Caught in Kelly Benefits Data Breach News 2 July 2025

Dozens of Corporates Caught in Kelly Benefits Data Breach

Thousands of Dollar Tree Staff Hit By Supplier Breach News 30 November 2023

Thousands of Dollar Tree Staff Hit By Supplier Breach

Some 98% of Global Firms Suffer Supply Chain Breach in 2021 News 10 November 2022

Some 98% of Global Firms Suffer Supply Chain Breach in 2021

What’s Hot on Infosecurity Magazine?

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

Multiple Class Action Lawsuits Filed Against IDScan

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

FulcrumSec Claims Responsibility for Manchester Airport Group Breach

FBI Probes Possible Breach of 153 Million Driver’s Licenses

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

Attackers Steal METR API Key and Burn $600,000 in AI Credits

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

65% of Enterprises Have Seen AI Agents Act Out of Scope

Hiring for the AI Era: A New Challenge for CISOs

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Securing M365 Data and Identity Systems Against Modern Adversaries

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

Predicting and Prioritizing Cyber Attacks Using Threat Intelligence

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities