A new Trezor data breach exposed personal records of 67,000 additional customers across the United States, as confirmed by the manufacturer in an official statement released on September 4, 2026. The incident originated at its logistics provider ShipMonk due to contractual noncompliance in purging order records fulfilled between November 2019 and August 2021.
Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.
— Trezor (@Trezor) September 4, 2026
Another 67,000 customers from the US who ordered between November 2019 and August 2021… https://t.co/yDQvTlAA2S
Exposed records contain full customer names, residential delivery addresses, email contacts, phone numbers, and purchase specifics. While Trezor emphasized that manufacturing pipelines and hardware firmware remain uncompromised, this leaked information fuels targeted impersonation efforts.
When an adversary ties hardware ownership to a residential address, physical user security faces an immediate critical threat outside digital boundaries. The danger intensifies because malicious actors design coordinated social engineering schemes utilizing verified purchase data to deceive hardware owners.
The core vulnerability stems from the true risk is your physical address rather than code exploits. By identifying a hardware owner holding substantial amounts in cryptocurrencies, criminals bypass cryptographic defenses through direct home extortion. Beyond physical harassment, unauthorized SIM swapping threats expand significantly when telephone records circulate across underground data marketplaces.
This exposure contradicts the limited scope Trezor announced on August 13. In its initial report, the manufacturer estimated that only 13,689 customers across seven nations suffered exposure following an unauthorized intrusion into Metabase, ShipMonk’s analytics software.
However, subsequent forensic auditing discovered that the logistics partner retained 67,000 legacy records belonging to American buyers. Trezor maintained it held binding written commitments requiring complete data deletion after 90 days, but the logistics partner retained confidential records without authorization over several consecutive operational cycles. In response, unpurged legacy orders multiplied the potential operational impact of the intrusion.
Unlawful record retention transforms the primary attack vector
The technical vector involved a critical SQL injection cataloged as CVE-2026-72898 inside Metabase, exploited by threat actors associated with ShinyHunters. This Trezor data breach demonstrates that third-party fulfillment constitutes an acute systemic risk. According to figures from cybersecurity firm Hacken, impersonation fraud caused 306 million in losses during the first quarter of 2024, representing 63% of the 482 million stolen across the industry. Attackers avoid breaking cryptographic keys; instead, cybercriminals prefer manipulating end users directly by weaponizing authentic transaction records.
Industry precedents underscore the chronic repetition of supply chain vulnerabilities. In January 2024, Trezor disclosed that 66,000 customers faced phishing risks following an intrusion into its third-party support portal. A comparable breach struck MailChimp in 2022, exposing thousands of subscriber emails.
Repeated hardware wallet security vulnerabilities show that physical security fails when external contractors mishandle sensitive data. Similar merchant database exposures occurred during the 2020 Ledger incident through its partner Global-e. Under these conditions, chronic vendor failures erode consumer trust across traditional distribution channels, while repeated customer data exposure magnifies fraud efficiency over extended horizons.
Direct financial damages emerge from deceptive transactions rather than chip vulnerabilities. In July 2024, a crypto investor surrendered nearly 1 million dollars after signing a fraudulent approval transaction on Ethereum. Following this Trezor data breach, malicious operators possess authentic names and telephone numbers to craft convincing pretexts.
For this reason, urgent demands to enter wallet recovery seeds must be rejected across every communication platform. Hardware manufacturers never request a twenty-four-word backup under any circumstances, and verifying announcements across official communication channels represents the only reliable safeguard against theft.
Trezor announced plans to expedite anonymous delivery options before the current quarter ends to restrict unnecessary home address storage. The 67,000 affected customers have already received individual email alerts detailing mandatory protective protocols. While ShipMonk concludes external forensic reviews, deploying neutral packaging without shipping identifiers will define the manufacturer’s updated logistics framework. Meanwhile, affected customers must monitor incoming correspondence closely throughout subsequent weeks for deceptive email or telephone outreach.

