Back Infosecurity-Magazine Trezor Supply Chain Breach Now Impacts 81,000 Customers
Cryptocurrency wallet manufacturer Trezor has revealed that a breach at a key shipping partner has affected 67,000 more customers than originally thought.
In an update posted on September 4, the hardware specialist said it was informed that the trove stolen from ShipMonk also included order data from the time period November 2019 – August 2021.
When the original breach notification was posted on August 13, the firm claimed that only data from between May 10 and August 8 2026 was involved.
The new victim count represents a 479% increase on the original estimate.
Full details were exposed in the incident, including customer names, emails, phone numbers, shipping addresses and order numbers.
“Be aware of the increased risk of phishing,” the firm warned. “The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks.”
Trezor customers have been a popular target for threat actors over the years. In 2022, it was forced to clarify that an email sent to customers warning of a major data breach at the firm was a scam designed to trick them into handing over their wallet recovery codes.
Trezor laid the blame for the recent breach firmly at the feet of its logistics partner, claiming that its data minimization policy wasn’t followed.
“Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications,” it wrote in a post on X (formerly Twitter). “We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems.”
Trezor said it was still deciding whether to take legal action against the firm.
“We are in direct with ShipMonk to establish exactly what happened and which data was reached. ShipMonk has secured the affected systems and hardened its security after the incident,” it continued.
“We are also speeding up work on anonymous delivery in our shop, so that in the future less personal data has to leave our systems at all, and in the meantime you can already keep what you to a minimum by using a PO box, parcel locker, or pickup point.”
Nissan: Thousands Impacted By Red Hat Breach News 23 December 2025
Nissan: Thousands Impacted By Red Hat Breach
US Data Breaches Head for Another Record Year After 11% Surge News 17 July 2025
US Data Breaches Head for Another Record Year After 11% Surge
Dozens of Corporates Caught in Kelly Benefits Data Breach News 2 July 2025
Dozens of Corporates Caught in Kelly Benefits Data Breach
Thousands of Dollar Tree Staff Hit By Supplier Breach News 30 November 2023
Thousands of Dollar Tree Staff Hit By Supplier Breach
Some 98% of Global Firms Suffer Supply Chain Breach in 2021 News 10 November 2022
Some 98% of Global Firms Suffer Supply Chain Breach in 2021
What’s Hot on Infosecurity Magazine?
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
Multiple Class Action Lawsuits Filed Against IDScan
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
FBI Probes Possible Breach of 153 Million Driver’s Licenses
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
Attackers Steal METR API Key and Burn $600,000 in AI Credits
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
65% of Enterprises Have Seen AI Agents Act Out of Scope
Hiring for the AI Era: A New Challenge for CISOs
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Securing M365 Data and Identity Systems Against Modern Adversaries
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
Predicting and Prioritizing Cyber Attacks Using Threat Intelligence
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
