Trezor Confirms Additional 67,000 US Customers Exposed in ShipMonk Data Breach

TL;DR
- ShipMonk breach expands to 67,000 more Trezor users
- All newly affected individuals are based in the United States
- Trezor urges users to monitor accounts and follow security guidance
Expanded Scope of the ShipMonk Incident
Trezor, the hardware‑wallet brand owned by SatoshiLabs, announced that a recent cyber‑attack on its third‑party logistics provider, ShipMonk, has now impacted an additional 67,000 customers. The breach was first reported earlier this month, and the latest figures were disclosed in a statement released on September 4, 2026. The newly identified data set includes personal information tied to Trezor orders that were processed through ShipMonk’s fulfillment services.
Who Is Affected?
According to the company's communication, the 67,000 newly exposed accounts belong to users located in the United States. This detail was highlighted by Cointelegraph, which noted that the breach specifically targets U.S. customers. The compromised data is reported to consist of names, email addresses, shipping details, and order histories, but does not include private keys or seed phrases that secure the wallets themselves. The breach does not appear to have exposed any cryptocurrency holdings directly.
Trezor’s Response and Recommendations
Trezor has urged all affected users to remain vigilant for phishing attempts and to verify any unsolicited communications that reference their purchase history. The company is working with ShipMonk to improve security protocols and has initiated an internal review of its supply‑chain data handling practices. Users are advised to update passwords on associated accounts, enable two‑factor authentication where available, and monitor their email inboxes for suspicious activity. Trezor also plans to provide additional guidance through its official support channels in the coming weeks.
Industry Context
The incident underscores the growing risk that third‑party service providers pose to the broader crypto ecosystem. While hardware wallets remain a strong line of defense for private key protection, the reliance on external logistics and fulfillment partners introduces new attack vectors. Security experts have repeatedly warned that supply‑chain vulnerabilities can lead to indirect exposure of user data, even when core wallet security remains intact.
Overall, the expanded breach does not change the fundamental security model of Trezor devices, but it does highlight the importance of comprehensive data protection across all stages of the customer journey. Users are encouraged to follow Trezor’s recommended security measures and stay informed about any further updates from the company.
This article was reconstructed from public reporting with AI assistance and is for informational purposes only — not financial advice. See our editorial policy.
Related
Senate Set for September 15 Vote on Crypto CLARITY Act Amid House Scheduling Delays
CFTC Moves to Dismiss CME Lawsuit Regarding Crypto Perpetual Futures
New Jersey Petitions Supreme Court Regarding Prediction Market Oversight
Sberbank Projects Significant Crypto Trading Volume Following Russian Regulatory Shift