type: incident ยท created: 2026-09-06 ยท updated: 2026-09-06 ยท tags: [incident, data-breach, supply-chain, financial-services] ยท confidence: high ยท affected_sectors: [finance] ยท au_impact: false
Trezor Says ShipMonk Breach Exposed ~67,000 More US Customers It Was Told Had Been Deleted
Summary
Hardware-wallet maker Trezor reported that the data breach at its third-party logistics provider ShipMonk โ first disclosed in mid-August as affecting about 13,700 customers โ was substantially larger, with order data from an earlier cooperation period (November 2019 to August 2021) also exposed for approximately 67,000 additional US customers.
Key Facts
- Data exposed: Full name, email address, phone number, shipping address and order number.
- Retention failure: Trezor said it repeatedly requested and received written confirmation from ShipMonk that the older data had been deleted in line with its 90-day retention policy, yet the data was retained and exposed.
- Scope: No wallet, seed or device data involved; Trezor's own systems were not compromised.
- Risk: Heightened phishing-and-impersonation attempts against affected customers, including fraudulent calls and letters.
Significance
The episode crystallises third-party data-retention risk: a contractual deletion obligation is only as real as the partner's actual retention behaviour, and written assurance of deletion is not the same as verification. It reinforces the supply-chain data-handling theme across financial and adjacent sectors.