Trezor has revealed that its logistics partner ShipMonk improperly retained order data older than expected, adding roughly 67,000 additional U.S. customers to those affected by the recent data breach. The newly exposed records stem from ShipMonk orders made between November 2019 and August 2021 that were supposed to have been purged. The total number of affected users across all impacted regions is now over 80,000.
Scope of Exposure & What Was Taken
The breach was first disclosed on August 13, following notification by ShipMonk on August 10 of unauthorized access that impacted customers whose names, email addresses, telephone numbers, and shipping addresses were fully exposed—alongside others whose data was partially exposed. Initial estimates placed the number of affected individuals at about 13,689 across several countries for orders placed between May and August 2026.
With the new revelation, the U.S.-based people impacted adds to around 67,000, including those whose data from old orders—orders that should have been deleted under Trezor’s data retention policy—remained in ShipMonk’s systems. Combined with the earlier disclosed group, affected individuals’ data includes names, emails, phone numbers, shipping addresses, and order histories.
What Went Wrong & Risks
The incident was traced to a vulnerability in ShipMonk’s analytics platform, Metabase. Attackers exploited a zero-day SQL injection flaw, ultimately gaining administrative access to customer and account data. Crucially, there was no breach of Trezor’s internal systems: neither device firmware nor wallet backups were exposed—and physical parcel contents were safe.
Despite a policy that requires order data to be anonymized or deleted 90 days after delivery, the older records should have been removed well before the breach. Trezor claims it repeatedly asked for written confirmation from ShipMonk that those records had indeed been wiped—but those assurances proved untrue.
What Trezor Is Saying & Doing
In response to the breach, Trezor has advised customers to be extra cautious with any requests for personal information unless they originate through verified channels. The company highlighted that this kind of data—names, addresses, phone numbers, and evidence of hardware-wallet purchases—can be harvested for phishing, identity fraud, or even physical impersonation attacks.
Notably, this is the first time since Trezor’s founding in 2013 that customer phone numbers and shipping addresses have been exposed in this way. The company is exploring an anonymous delivery option, including locker pickups and automatic removal of identifying shipping details, to avoid similar issues in the future.
Why this matters: The breach underscores the gap between data-retention policies and reality when third parties are involved. For security-conscious users—especially those using hardware wallets—this kind of exposure isn’t just online risk; it can translate to real-world threats.
What to watch: Whether Trezor’s future data-deletion commitments are verifiable and how third-party vendors like ShipMonk will be held to tighter audit standards. Also, whether similar leaks occur in this sector, given latent data stored beyond policy limits can be a widespread weak point.