Hardware wallet maker Trezor has confirmed that a data breach at logistics partner ShipMonk is substantially larger than first reported, after older U.S. order records that should have been deleted remained in the leaked dataset.
On September 4, 2026, Trezor said it was told two days earlier that the incident also included order data from a prior ShipMonk partnership between November 2019 and August 2021, fully exposing about 67,000 additional U.S. customers.
Trezor first disclosed the incident on August 13 after ShipMonk reported unauthorized access on August 10. That notice covered 11,742 customers whose names, emails, phone numbers and shipping addresses were fully exposed, plus 1,947 with partial exposure of name, city and email, totaling about 13,689 people.
Those records were linked to orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8, 2026. An August 14 update already admitted that some partial-exposure records included older orders.
ShipMonk told customers that attackers exploited a vulnerability in the analytics platform Metabase. Metabase notified the logistics firm on August 6 that an unauthorized party used a software flaw to reach account and customer data. Later reporting tied the campaign to a critical SQL injection zero-day that yielded administrator access on compromised instances. Trezor’s own systems were not breached, its devices remain secure, and wallet backups were not leaked. Parcel contents were not exposed.
The latest update undercuts the retention argument Trezor used to bound the first disclosure. The company requires fulfillment partners to delete or anonymize order data 90 days after delivery. Trezor said it repeatedly requested and received written assurance that ShipMonk had deleted the older records, yet the data was still in ShipMonk’s systems.
The newly acknowledged U.S. files include name, email, phone number, shipping address, and order number, bringing the overall impact above 80,000 customers.
That combination of home addresses, phone numbers and hardware-wallet purchase history is useful for phishing and, Trezor now warns, physical security risk.
Scammers can impersonate Trezor, banks, or exchanges by email, call, or letter and push victims to enter a recovery seed. Affected customers have been emailed from [email protected]; anyone who did not receive that message is not in the leaked set.
Recipients should treat urgent requests for personal data as hostile, verify claims only through official Trezor channels, and never type a wallet backup into a website or share it with anyone.
Trezor said this is the first incident since its 2013 founding to expose customer phone numbers and shipping addresses, and it is preparing an Anonymous Delivery option with locker pickup and automatic deletion of shipping identifiers.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers appeared first on Cyber Security News.
