---
title: "Trezor breach reaches 81,000 customers because… | Firevault"
description: "A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/trezor-shipmonk-data-breach-81000-customers-2026#webpage",
      "url": "https://fire-vault.com/news/trezor-shipmonk-data-breach-81000-customers-2026",
      "name": "Trezor breach reaches 81,000 customers because…",
      "description": "A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/trezor-shipmonk-data-breach-81000-customers-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/trezor-shipmonk-data-breach-81000-customers-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Trezor breach reaches 81,000 customers because a supplier never deleted the data",
          "item": "https://fire-vault.com/news/trezor-shipmonk-data-breach-81000-customers-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Trezor breach reaches 81,000 customers because a supplier never deleted the data",
      "description": "A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.",
      "url": "https://fire-vault.com/news/trezor-shipmonk-data-breach-81000-customers-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-08T12:15:00+00:00",
      "dateModified": "2026-09-08T13:04:08.443453+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/trezor-shipmonk-data-breach-81000-customers-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 597,
      "keywords": "Trezor, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "## What happened Trezor, the cryptocurrency hardware wallet manufacturer, has confirmed that the August breach at its shipping and logistics provider ShipMonk affects 81,000 customers in total, up from the nearly 14,000 disclosed on 13 August. The original disclosure covered customers in Brazil, Colombia, Italy, Portugal, Sweden and the United Kingdom who received orders between 10 May and 8 Augus",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "How many Trezor customers were affected?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "81,000 in total. Nearly 14,000 were disclosed on 13 August 2026, and a further 67,000 US customers who ordered between November 2019 and August 2021 were confirmed in the September update."
          }
        },
        {
          "@type": "Question",
          "name": "What data was exposed?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Full names, email addresses, phone numbers, shipping addresses and, for the US group, order numbers. No wallet data was involved."
          }
        },
        {
          "@type": "Question",
          "name": "Were Trezor devices or wallets compromised?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Trezor says its own systems were not compromised, operations and services were unaffected, and all devices remain secure. The breach happened at its shipping and logistics provider."
          }
        },
        {
          "@type": "Question",
          "name": "Why were records from 2019 still there?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Trezor says the provider failed to delete the data as required by contract and data policy, despite repeatedly giving written confirmation that deletion had taken place."
          }
        },
        {
          "@type": "Question",
          "name": "How was the supplier breached?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Breach notifications indicate attackers exploited a critical SQL injection zero-day in the third-party analytics platform Metabase to gain administrator access and steal data. The same campaign affected Tally and Framework, and the provider reportedly received extortion emails from the ShinyHunters group."
          }
        },
        {
          "@type": "Question",
          "name": "What should affected customers do?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Treat unexpected emails, calls and letters with suspicion, never share recovery seed words or verification codes with anyone for any reason, verify any contact independently, and be alert to physical security risk given that home addresses were exposed."
          }
        },
        {
          "@type": "Question",
          "name": "Would Offline Secure Storage have prevented this?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. The failure was at a supplier, in a connected analytics platform. The relevant lesson is retention discipline: verify destruction rather than accept assurances, and hold data you must keep offline and immutable so no internet-facing system can export it."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Breaking News Updated as information becomes available 

Overview

What happenedThe part that mattersHow the supplier was breachedWhy this is worse than it looksThe Firevault viewSourceMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 8 September 2026 · Breaking 

# Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftrezor-shipmonk-data-breach-81000-customers-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftrezor-shipmonk-data-breach-81000-customers-2026&text=Trezor%20breach%20reaches%2081%2C000%20customers%20because%20a%20supplier%20never%20deleted%20the%20data%0A%0AA%20further%2067%2C000%20US%20customers%20who%20ordered%20between%202019%20and%202021%20were%20exposed%2C%20because%20Trezor's%20logistics%20provider%20kept%20data%20it%20had%20confirmed%20in%20writing%20it%20had%20deleted.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftrezor-shipmonk-data-breach-81000-customers-2026)[](mailto:?subject=Trezor%20breach%20reaches%2081%2C000%20customers%20because%20a%20supplier%20never%20deleted%20the%20data&body=A%20further%2067%2C000%20US%20customers%20who%20ordered%20between%202019%20and%202021%20were%20exposed%2C%20because%20Trezor's%20logistics%20provider%20kept%20data%20it%20had%20confirmed%20in%20writing%20it%20had%20deleted.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Ftrezor-shipmonk-data-breach-81000-customers-2026)

![Illustration of a split shipping parcel with customer address records spilling out beside an intact hardware wallet device, representing the Trezor supplier data breach](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Illustration of a split shipping parcel with customer address records spilling out beside an intact hardware wallet device, representing the Trezor supplier data breach

Why it matters

## What this means for organisations holding critical data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [The part that matters](#section-1)
3.  03 [How the supplier was breached](#section-2)
4.  04 [Why this is worse than it looks](#section-3)
5.  05 [The Firevault view](#section-4)

**On this page**[What happened](#section-0)[The part that matters](#section-1)[How the supplier was breached](#section-2)[Why this is worse than it looks](#section-3)[The Firevault view](#section-4)

## What happened

Trezor, the cryptocurrency hardware wallet manufacturer, has confirmed that the August breach at its shipping and logistics provider ShipMonk affects 81,000 customers in total, up from the nearly 14,000 disclosed on 13 August.

The original disclosure covered customers in Brazil, Colombia, Italy, Portugal, Sweden and the United Kingdom who received orders between 10 May and 8 August 2026, exposing full names, shipping addresses, email addresses and phone numbers.

The update adds a further 67,000 US customers who ordered between November 2019 and August 2021, with names, email addresses, phone numbers, shipping addresses and order numbers exposed.

## The part that matters

Those 67,000 records should not have existed. Trezor states plainly that ShipMonk failed to delete the data as required by contract and data policy, despite repeatedly giving written confirmation that it had done so.

"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," Trezor said. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."

Trezor says its own systems were not compromised, its operations and services were unaffected, and all devices remain secure.

## How the supplier was breached

Breach notification emails seen by BleepingComputer say the attackers exploited a vulnerability in Metabase, the third-party analytics platform. Metabase has confirmed that attackers used a critical SQL injection zero-day to gain administrator access to customer instances and steal data. Other victims of the same campaign include the form-building platform Tally and the laptop maker Framework. BleepingComputer reports that ShipMonk has received extortion emails from the ShinyHunters group.

This is also not Trezor's first exposure through a third party. In January 2024 a compromised support ticketing portal exposed names, usernames and email addresses of around 66,000 users, and that data was later used in phishing attacks attempting to harvest 24-word wallet recovery seeds.

## Why this is worse than it looks

For most companies a leaked name and postal address is a phishing risk. For a hardware wallet customer it is a list of households that plausibly hold cryptocurrency at a known physical address, with a verified phone number attached. Trezor said as much, warning of scam emails, fraudulent calls and letters, and potential physical security risk.

The record retention failure is the lesson for everyone else. Deletion was contracted, requested and confirmed in writing, and none of that made the data go away. A written assurance is not a control.

## The Firevault view

[Offline Secure Storage](/offline-secure-storage)® would not have patched Metabase or governed ShipMonk's housekeeping. This was a supplier's connected analytics platform, exploited through a zero-day.

The Firevault point is about retention discipline. Data that must be kept is safest offline and immutable, where nothing reachable from the internet can export it. Data that must be destroyed has to be verifiably destroyed, not attested. Any organisation relying on a supplier's word should ask what evidence of deletion exists, where the copies were, and who could still read them, because the answers here were reassuring and wrong for five years.

Mark Fermor, Director and Co-Founder of Firevault, said: "Trezor did the responsible thing. It contracted for deletion, it asked repeatedly, and it got written confirmation. Records from 2019 still went out of the door in 2026. If you cannot prove a copy is gone, treat it as live, and treat everything you must retain as something to hold offline rather than leave in reach."

## Source

-   [BleepingComputer: Trezor data breach impact now reaches 81,000 customers](https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/)

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Quinn Emanuel and McDermott breached as law firms become the soft route to client data](/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg)

Breach Analysis 

### Quinn Emanuel and McDermott breached as law firms become the soft route to client data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

8 Sept 2026 4 min 







](/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026)[

![Mathspace breach exposes more than one million students, staff and parents](/images/news/mathspace-data-breach-one-million-students-2026.jpg)

Breach Analysis 

### Mathspace breach exposes more than one million students, staff and parents

An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

8 Sept 2026 4 min 







](/news/mathspace-data-breach-one-million-students-2026)[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)[

![Cornelius faces legal investigation after alleged Cl0p cyber attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/cornelius-alleged-clop-ransomware-data-breach-1786684482605.png)

Breach Analysis 

### Cornelius faces legal investigation after alleged Cl0p cyber attack

Cornelius faces legal scrutiny following reports of a Cl0p ransomware breach in August 2026. Claims suggest thousands of gigabytes of corporate data were compromised.

14 Aug 2026 4 min 







](/news/cornelius-alleged-clop-ransomware-data-breach)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)