Trezor Expands ShipMonk Breach Disclosure to 67,000 More US Customers
SatoshiLabs reported on 4 September 2026 that a shipping partner breach now affects an additional 67,000 US Trezor customers, bringing the total exposed to roughly 80,689.
Trezor, operated by SatoshiLabs, stated on 4 September 2026 that a breach at shipping partner ShipMonk now affects an additional roughly 67,000 US customers who placed orders between November 2019 and August 2021.
The exposed data fields include name, email, phone number, shipping address, and order number.
Combined with the earlier disclosure of 13,689 affected customers, the total number of users at risk stands at approximately 80,689.
Risks and response
The exposed contact and address information raises the risk of targeted phishing, fraudulent calls or texts, direct-mail scams, and physical security threats for hardware-wallet holders.
Trezor attributed the expanded scope to ShipMonk’s failure to delete customer data after the required 90-day retention period, despite written assurances that the data had been removed.
The company said it is accelerating options for anonymous delivery of its products.
Open questions
It remains unstated whether any of the exposed data has been misused or sold.
The exact final user count and any regulatory notifications have not been disclosed.