Trezor breach reaches 81,000 customers because a supplier never deleted the data
A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

Why it matters
What this means for organisations holding critical data
A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.
What happened
Trezor, the cryptocurrency hardware wallet manufacturer, has confirmed that the August breach at its shipping and logistics provider ShipMonk affects 81,000 customers in total, up from the nearly 14,000 disclosed on 13 August.
The original disclosure covered customers in Brazil, Colombia, Italy, Portugal, Sweden and the United Kingdom who received orders between 10 May and 8 August 2026, exposing full names, shipping addresses, email addresses and phone numbers.
The update adds a further 67,000 US customers who ordered between November 2019 and August 2021, with names, email addresses, phone numbers, shipping addresses and order numbers exposed.
The part that matters
Those 67,000 records should not have existed. Trezor states plainly that ShipMonk failed to delete the data as required by contract and data policy, despite repeatedly giving written confirmation that it had done so.
"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," Trezor said. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."
Trezor says its own systems were not compromised, its operations and services were unaffected, and all devices remain secure.
How the supplier was breached
Breach notification emails seen by BleepingComputer say the attackers exploited a vulnerability in Metabase, the third-party analytics platform. Metabase has confirmed that attackers used a critical SQL injection zero-day to gain administrator access to customer instances and steal data. Other victims of the same campaign include the form-building platform Tally and the laptop maker Framework. BleepingComputer reports that ShipMonk has received extortion emails from the ShinyHunters group.
This is also not Trezor's first exposure through a third party. In January 2024 a compromised support ticketing portal exposed names, usernames and email addresses of around 66,000 users, and that data was later used in phishing attacks attempting to harvest 24-word wallet recovery seeds.
Why this is worse than it looks
For most companies a leaked name and postal address is a phishing risk. For a hardware wallet customer it is a list of households that plausibly hold cryptocurrency at a known physical address, with a verified phone number attached. Trezor said as much, warning of scam emails, fraudulent calls and letters, and potential physical security risk.
The record retention failure is the lesson for everyone else. Deletion was contracted, requested and confirmed in writing, and none of that made the data go away. A written assurance is not a control.
The Firevault view
Offline Secure Storage® would not have patched Metabase or governed ShipMonk's housekeeping. This was a supplier's connected analytics platform, exploited through a zero-day.
The Firevault point is about retention discipline. Data that must be kept is safest offline and immutable, where nothing reachable from the internet can export it. Data that must be destroyed has to be verifiably destroyed, not attested. Any organisation relying on a supplier's word should ask what evidence of deletion exists, where the copies were, and who could still read them, because the answers here were reassuring and wrong for five years.
Mark Fermor, Director and Co-Founder of Firevault, said: "Trezor did the responsible thing. It contracted for deletion, it asked repeatedly, and it got written confirmation. Records from 2019 still went out of the door in 2026. If you cannot prove a copy is gone, treat it as live, and treat everything you must retain as something to hold offline rather than leave in reach."
Source
Sources
Where this reporting comes from
How Firevault would handle this
A recovery copy an attacker cannot reach
Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.






