Trezor faces data exposure as 67,000 more customers’ information leaks through shipping partner

1 week ago 6



Trezor built its reputation on keeping private keys safe. The company has less control, it turns out, over what its shipping partners do with customer mailing addresses. On September 4, 2026, Trezor disclosed that an additional 67,000 US customers had their personal data exposed, on top of the roughly 13,700 already notified in an August 13 disclosure. The running total now sits at approximately 80,700 people whose full names, email addresses, physical shipping addresses, and phone numbers are floating somewhere they shouldn’t be. The culprit is ShipMonk, Trezor’s shipping and fulfillment partner. The breach itself was traced to a SQL-injection vulnerability in ShipMonk’s Metabase analytics platform, first reported around August 6, 2026. In ShipMonk’s case, that meant unauthorized access to customer records Trezor had reasonably assumed were long gone. A promise that didn’t survive contact with reality The 67,000 newly exposed customers placed orders between 2019 and 2021, records that should have been purged. Trezor says it received written assurances from ShipMonk that older data would be securely deleted. Those assurances, in Trezor’s own phrasing, were not honored. The initial ...

Read Entire Article