www.infosecurity-magazine.com 8 Sept 2026, 09:08 UTC

Trezor Data Breach Expands by 67,000 After ShipMonk Exposure

CyberSIXT Evidence Panel Source marked as original reporting

TREZOR has disclosed that a breach at its shipping partner, ShipMonk, has expanded the scope of affected customers well beyond initial estimates. An update dated 4 September 2026 confirms that data stolen from ShipMonk also encompassed order data from November 2019 to August 2021, meaning the total victim count has risen by 67,000 and represents a 479% increase on the original figure. The firm previously indicated that only data from May 10 to 8 August 2026 was involved when the breach was first reported on 13 August 2026.

The exposed information includes customer names, emails, phone numbers, shipping addresses and order numbers. Trezor has attributed the surge in impact to a breach at its logistics provider and criticised ShipMonk for not deleting data in breach of its data minimisation commitments. The company says it is in direct contact with ShipMonk to establish exactly what happened and what data was accessed, with ShipMonk reporting that affected systems have been secured and its security posture tightened since the incident. Trezor is also weighing potential legal action.

In response, Trezor signalled moves to reduce the amount of personal data leaving its systems, including an initiative to offer anonymous deliveries and encourage customers to use PO boxes, parcel lockers, or pickup points. The firm urged customers to be vigilant for phishing, scams, or fraudulent communications that might leverage the leaked data.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline