Trezor Breach Expands to 67,000 US Customers as 2019 Records Surface
An additional 67,000 US customers had their data exposed in a breach tied to ShipMonk, Trezor's third-party shipping provider. Some records date to 2019, well beyond the 90-day retention window Trezor's vendor partners contractually agreed to observe.
Trezor Breach Expands to 67,000 US Customers as 2019 Records Surface
An additional 67,000 US customers had their data exposed in a breach tied to ShipMonk, Trezor's third-party shipping provider, the hardware wallet maker disclosed this week. The announcement expands the known scope of an incident that was already damaging for a company whose core value proposition is security.
The detail that has drawn the sharpest scrutiny is not the headcount but the timestamps. Some of the exposed records date to 2019, a full seven years ago, well beyond the 90-day data retention window that Trezor says its vendor partners contractually agreed to observe. In a statement, Trezor acknowledged that "some records exposed in the breach date to 2019, years beyond the 90-day retention Trezor said its partners had agreed to." That gap between contractual obligation and actual practice points to a vendor oversight failure that no amount of in-house security architecture could have caught.
The breach did not touch Trezor's own systems. ShipMonk, a logistics and fulfillment provider, was the point of compromise, meaning the hardware wallets themselves and the cryptographic key management they handle were not affected. Trezor has been consistent in noting that exposed shipping and customer records do not, on their own, give attackers access to private keys or funds. Users who follow standard security practices, keeping seed phrases offline and treating unsolicited contact with suspicion, face no direct risk to their holdings.
The practical danger lies elsewhere. Shipping data typically contains names, addresses, and order histories. For hardware wallet buyers, that information is a targeting list. Attackers who know a person purchased a Trezor device have a ready-made pretext for phishing campaigns: fake firmware update notices, counterfeit support requests, and social engineering calls that reference real order details to appear credible.
The 67,000 figure covers US customers only. Trezor has not yet disclosed whether additional users in other jurisdictions were similarly affected, leaving the full global scope unresolved.
This is not Trezor's first encounter with third-party data exposure. The company disclosed a separate incident earlier in 2024 involving unauthorized access to a support-ticket database managed by an external provider. Hardware wallet manufacturers invest heavily in the cryptographic security of their devices while the surrounding operational infrastructure, logistics partners, CRM vendors, and support platforms remain softer targets. Ledger faced similar reputational damage in 2020 when a marketing database breach exposed the names and addresses of roughly 270,000 customers, and the resulting phishing wave lasted for years. Trezor's current situation tracks that precedent closely.
The retention violation is the element most likely to attract regulatory attention. Data minimization and defined retention periods are foundational requirements under frameworks like the California Consumer Privacy Act and, for any customers in the European Union, the General Data Protection Regulation. Holding records from 2019 under a 90-day contractual ceiling is not a gray area. Whether regulators in either jurisdiction treat this as an enforcement priority will depend partly on what categories of personal data were involved and whether Trezor can demonstrate it had reasonable contractual controls in place, even if those controls were not enforced by the vendor.
Trezor's decision to proactively expand its disclosure, rather than wait for independent researchers or regulators to surface the fuller picture, is a meaningful distinction. Transparency after a breach does not undo the underlying failure, but it does affect how regulators and customers weigh the company's good faith. The more pressing obligation now is a clear accounting of how many total customers were affected globally, what specific data fields were exposed, and what remediation Trezor is requiring of ShipMonk going forward.
Affected US customers should treat any inbound communication referencing their Trezor purchase as suspect, regardless of how detailed or official it appears. Trezor will not ask for seed phrases through any channel.






