Market Incident

Public · Developing

Users exposed by Trezor breach grows sixfold after supposedly deleted shipping logs are found

The number of users affected by the Trezor data breach has increased sixfold to about 80,689 after supposedly deleted shipping logs were found. The exact overlap between the new and old data has not been publicly combined or verified.

Published:

Updated:

What happened

Trezor has disclosed that a breach at its shipping partner ShipMonk exposed personal and order details for about 80,689 customers. The number grew after shipping logs that were supposed to be deleted were found. Some data dates from 2019–2021.

Global impact / market context

This matters because personal details like names and shipping addresses of Trezor customers may now be in the hands of unknown attackers. Such information can be used for targeted scams, phishing, or other fraud. It also raises concerns about the company’s handling of deleted data and customer privacy.

What to watch

  1. Check whether Trezor provides a clear update on how many customers are affected after combining the old and new data sets, because the exact overlap is not yet known.
  2. Watch for any official confirmation from ShipMonk or Trezor about the root cause of the breach and whether any data was actually accessed or misused, as this is not currently stated.
  3. Look for guidance from Trezor on what affected customers should do next, such as changing passwords or being alert for phishing emails, because no such instructions have been shared publicly yet.

Evidence