{"id":1032,"date":"2026-08-15T05:24:27","date_gmt":"2026-08-15T05:24:27","guid":{"rendered":"https:\/\/bitjunki.com\/index.php\/2026\/08\/15\/trezor-discloses-expanded-data-breach-affecting-tens-of-thousands-more-customers-after-third-party-fulfillment-failure\/"},"modified":"2026-08-15T05:24:27","modified_gmt":"2026-08-15T05:24:27","slug":"trezor-discloses-expanded-data-breach-affecting-tens-of-thousands-more-customers-after-third-party-fulfillment-failure","status":"publish","type":"post","link":"https:\/\/bitjunki.com\/index.php\/2026\/08\/15\/trezor-discloses-expanded-data-breach-affecting-tens-of-thousands-more-customers-after-third-party-fulfillment-failure\/","title":{"rendered":"Trezor Discloses Expanded Data Breach Affecting Tens of Thousands More Customers After Third-Party Fulfillment Failure"},"content":{"rendered":"<p>Prague-based cryptocurrency hardware wallet manufacturer Trezor has revealed that a data breach initially disclosed last month is significantly more widespread than previously reported, exposing the personal information of tens of thousands of additional customers. According to an updated statement released by the Czech Republic-based company, an additional 67,000 customers in the United States have had their sensitive personal records compromised as a direct result of an unauthorized intrusion at its external fulfillment partner.<\/p>\n<p>The expanded dataset includes customer names, email addresses, phone numbers, physical shipping addresses, and specific order numbers tied to purchases placed between November 2019 and August 2021. In addition to the primary group of impacted U.S. customers, Trezor confirmed that another 1,947 customers had a subset of their personal information\u2014specifically their names, cities, and email addresses\u2014exposed during the same security incident.<\/p>\n<p>The latest disclosure drastically increases the total scope of the incident compared to the figures Trezor presented when it first went public with the breach in August. At that time, the company reported that an unauthorized third party had accessed systems belonging to its shipping fulfillment provider, resulting in the exposure of data belonging to 11,742 customers spread across seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. That initial batch of compromised records included names, email addresses, phone numbers, and physical shipping locations.<\/p>\n<p>The dramatic shift in the scale of the breach stems from ongoing discoveries regarding how customer data was retained by Trezor\u2019s third-party shipping and logistics partner, ShipMonk. According to Trezor, the fulfillment company had repeatedly assured the hardware manufacturer that legacy customer information was being routinely purged from its internal databases in compliance with privacy guidelines and contractual obligations.<\/p>\n<p>In its public disclosure detailing the revised numbers, Trezor expressed frustration over the logistics provider\u2019s handling of customer records, pointing out a stark discrepancy between written policy compliance guarantees and the actual state of data retention within ShipMonk\u2019s storage infrastructure. Trezor stated that throughout its commercial relationship with ShipMonk, it had consistently requested and received formal written assurances confirming that customer data was being routinely deleted in alignment with contractual terms, established data management policies, and historical communications.<\/p>\n<p>Trezor expressed deep disappointment that despite receiving repeated official confirmations that customer information was being systematically removed, the data remained stored within ShipMonk&#8217;s systems, where it subsequently became accessible to unauthorized attackers. The hardware maker noted that it had recently received an updated assessment from ShipMonk detailing the true extent of the retained records, prompting the immediate public update to inform affected users.<\/p>\n<p>Neither Trezor nor ShipMonk provided immediate responses to requests for additional comment regarding the precise vector of the system breach, the exact date the intrusion occurred, or the specific security measures being implemented to prevent further exposure.<\/p>\n<p>The incident originally came to light in August when Trezor announced that ShipMonk had suffered unauthorized access to internal systems housing historical e-commerce order data. In response to the initial finding, SatoshiLabs, the parent company of Trezor, launched an internal investigation to evaluate the incident&#8217;s scope and assess the operational practices of its supply chain partners.<\/p>\n<p>Trezor has stated that it took immediate steps to notify every customer identified in both the initial and expanded breach datasets. Direct email communications have been dispatched to all affected users to alert them that their order history and personal contact details were exposed, advising them to remain vigilant against potential follow-up threats.<\/p>\n<p>While Trezor is widely recognized as one of the premier hardware wallet solutions in the global cryptocurrency industry\u2014offering physical storage devices designed to secure Bitcoin and a vast array of alternative digital assets\u2014the compromise of e-commerce data highlights a persistent vulnerability for hardware manufacturers. Hardware wallets themselves are specifically engineered to keep a user\u2019s private cryptographic keys completely isolated from internet-connected environments, making the physical devices resilient against remote hacking attempts. However, the external administrative, shipping, and sales databases managed by third-party partners remain traditional targets for cybercriminals.<\/p>\n<p>For users of cryptocurrency hardware wallets, the exposure of personal identifying information carries risks that extend beyond standard e-commerce data leaks. When cybercriminals acquire databases containing the physical shipping addresses, phone numbers, and order histories of cryptocurrency users, they gain actionable intelligence that links specific individuals to cryptocurrency ownership. This data can be weaponized in targeted social engineering campaigns, highly sophisticated phishing attempts, phone-based SIM-swapping attacks, or direct physical extortion threats aimed at forcing victims to relinquish control of their digital assets.<\/p>\n<p>The situation surrounding Trezor and ShipMonk mirrors similar high-profile data security incidents that have affected the hardware wallet sector in recent years. Cybercriminals have repeatedly targeted e-commerce databases associated with digital asset storage solutions, recognizing that the customer lists of hardware wallet vendors represent highly lucrative targets for targeted fraud.<\/p>\n<p>A notable parallel occurred in 2020, when Trezor&#8217;s primary market competitor, Ledger, suffered a massive data security breach. In that incident, an unauthorized third party gained entry to Ledger\u2019s e-commerce and marketing databases, leading to the public leak of more than 1 million email addresses. Furthermore, the breach exposed the detailed personal contact information\u2014including full physical addresses and phone numbers\u2014of nearly 10,000 customers. The leaked data was subsequently circulated on public forums, resulting in widespread, targeted phishing campaigns aimed at Ledger users, with attackers attempting to trick victims into revealing their recovery seed phrases through fraudulent software updates and malicious communications.<\/p>\n<p>Ledger faced further supply chain security challenges earlier this year when its third-party payment processing partner, Global-e, experienced a breach within its cloud-based storage environment. Ledger customers reported receiving official communications informing them that sensitive transaction and personal data managed by the payment partner had been accessed without authorization during that cloud intrusion.<\/p>\n<p>These recurring breaches across multiple industry leaders highlight the systemic challenges cryptocurrency hardware companies face when managing third-party operational risk. While a hardware wallet manufacturer can implement rigorous cryptographic standards and strict security controls on the physical devices it builds, its overall security posture remains interconnected with external logistics providers, payment gateways, order fulfillment centers, and marketing vendors. When these third-party entities fail to enforce rigorous data deletion standards or maintain adequate defensive measures, historical customer records can linger in accessible cloud storage environments long after transactions are completed.<\/p>\n<p>Trezor\u2019s parent organization, SatoshiLabs, continues to investigate the circumstances that allowed years of legacy order data to remain stored on ShipMonk\u2019s infrastructure despite contractual agreements mandating its destruction. As the investigation proceeds, the company\u2019s primary focus remains on notifying affected individuals, providing guidance on how to identify potential phishing scams, and reassessing its third-party fulfillment pipeline to prevent similar vulnerabilities from compromising customer privacy in the future.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Prague-based cryptocurrency hardware wallet manufacturer Trezor has revealed that a data breach initially disclosed last month is significantly more widespread than previously reported, exposing the personal information of tens of thousands of additional customers. According to an updated statement released by the Czech Republic-based company, an additional 67,000 customers in the United States have had [&hellip;]<\/p>\n","protected":false},"author":23,"featured_media":1031,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[234],"tags":[1254,236,238,258,235,1257,223,239,1252,237,1253,926,1260,1259,1255,1258,1256,257],"class_list":["post-1032","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency-blockchain","tag-affecting","tag-bitcoin","tag-blockchain","tag-breach","tag-crypto","tag-customers","tag-data","tag-defi","tag-discloses","tag-ethereum","tag-expanded","tag-failure","tag-fulfillment","tag-party","tag-tens","tag-third","tag-thousands","tag-trezor"],"_links":{"self":[{"href":"https:\/\/bitjunki.com\/index.php\/wp-json\/wp\/v2\/posts\/1032","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitjunki.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitjunki.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitjunki.com\/index.php\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/bitjunki.com\/index.php\/wp-json\/wp\/v2\/comments?post=1032"}],"version-history":[{"count":0,"href":"https:\/\/bitjunki.com\/index.php\/wp-json\/wp\/v2\/posts\/1032\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitjunki.com\/index.php\/wp-json\/wp\/v2\/media\/1031"}],"wp:attachment":[{"href":"https:\/\/bitjunki.com\/index.php\/wp-json\/wp\/v2\/media?parent=1032"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitjunki.com\/index.php\/wp-json\/wp\/v2\/categories?post=1032"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitjunki.com\/index.php\/wp-json\/wp\/v2\/tags?post=1032"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}