ThreatCluster

ShipMonk Data Breach Affects 67,000 Trezor Customers

First seen 4 Sep 2026, 14:46 UTC CybersecuritynewsGbhackers 53

Article Content

Browse articles
ThreatCluster

Trezor has confirmed that a data breach involving its fulfillment provider, ShipMonk, has exposed personal and order information of approximately 67,000 additional U.S. customers. This breach significantly expands the scope of an incident initially reported in August 2026. The exposed data includes older U.S. order records that should have been deleted but remained in the leaked dataset. The breach relates to Trezor orders processed during a partnership with ShipMonk that lasted from November 2019 to 2021. As of September 4, 2026, Trezor has acknowledged the breach and is working to inform affected customers. The incident raises concerns about data retention practices and the handling of sensitive customer information by third-party vendors.

Key Points: • 67,000 additional Trezor customers affected by ShipMonk data breach. • Older order records that should have been deleted were leaked. • Breach significantly expands the scope of an earlier reported incident.

Ask AI about this cluster

Timeline

2026-08-01
Initial data breach reported
Trezor first reported a data breach involving ShipMonk, affecting an unspecified number of customers.
Gbhackers
2026-09-02
Trezor informed of expanded breach
Trezor was notified that the breach included additional data from older U.S. orders.
Cybersecuritynews
2026-09-04
Trezor confirms breach details
Trezor publicly confirmed the breach affecting 67,000 additional customers and the nature of the leaked data.
Gbhackers