Trezor Expands Breach Disclosure to 67,000 More Customers
Trezor’s Sept. 4 update adds roughly 67,000 U.S. customers exposed through retained shipping logs at vendor ShipMonk, bringing the known total near 80,689 while wallet systems stay unaffected.

Trezor expanded its breach disclosure on Sept. 4 to include roughly 67,000 additional U.S. customers whose contact and order data remained in the systems of logistics vendor ShipMonk after the company had received written assurances that the records had been deleted.
The new cohort covers U.S. orders placed between November 2019 and August 2021. Combined with the 13,689 customers named in the initial Aug. 13 disclosure, the two groups imply a total of roughly 80,689 affected individuals, though Trezor has not published a single combined figure or confirmed whether any records overlap.
What remains unknown
Exposed fields are limited to names, email addresses, phone numbers, shipping addresses and order numbers. Trezor stated that its own systems, devices, keys and funds were not reached and that the risk is confined to the possibility of targeted scams or physical approaches based on the purchase trail.
The company said it emailed every newly identified customer directly. No confirmed downstream attacks from the dataset have been reported. The exact combined total and any row-level overlap between the two cohorts remain unpublished.