Privacy & Data 6 min read

Trezor's Breach Reached 81,000 Because Its Shipping Vendor Kept Data It Promised to Delete

The 67,000 records added are orders from 2019 to 2021, held by a shipping provider that gave written assurances of deletion. The order number identifies the product.

Priya Nair
Data, AI Governance & Policy Analyst
Published 8 Sep 2026, 9:12 PM (SGT)
Share:
Shrink-wrapped air cargo pallets lined up on an airport apron beside a loading vehicle. Shrink-wrapped air cargo pallets lined up on an airport apron beside a loading vehicle. Photo by PublicDomainPictures on Pixabay
Advertisement

8 SEP 2026 — Trezor now says 81,000 customers were exposed in a breach at its shipping provider, up from about 14,000 disclosed in August. The 67,000 added on 4 September are orders from November 2019 to August 2021 — records the provider was contractually required to delete and had given written assurances it had deleted.

Two disclosures, two different problems

The August disclosure covered customers in Brazil, Colombia, Italy, Portugal, Sweden and the United Kingdom who ordered between 10 May and 8 August 2026. That is a breach of current operational data, which is unwelcome and unsurprising.

The September update is a different kind of finding. The stolen trove at ShipMonk also held United States order data from November 2019 to August 2021 — between five and seven years old, from a period the processor had no business retaining.

Trezor says it repeatedly asked ShipMonk to delete customer data throughout the relationship and received written assurances, in line with the contract and its own data policy, that the information had been removed.

81,000Customers now affected, from about 14,000 in August
67,000Added on 4 September, all United States orders
2019–2021The period those records cover
Written assurancesWhat the processor gave that the data was deleted

Retention failure is the story, not breach size

The number went up because old data existed, not because the attackers got further. If the deletion had happened when it was contracted, agreed and confirmed, the September update would not exist and the incident would have stayed at 14,000.

That reframes what went wrong. The security failure at ShipMonk is one problem; the governance failure — a processor holding personal data for years past its purpose while telling the controller it had gone — is the one that turned a moderate incident into a large one.

It is also the more common failure. Deletion is unglamorous, nobody audits it until something goes wrong, and a written assurance costs a supplier nothing to give and is almost never verified.

Why these particular records matter more

The exposed fields are names, email addresses, phone numbers, shipping addresses and order numbers. On their own that is a standard e-commerce breach set.

The order number changes the picture. It identifies the product, and the product is a hardware cryptocurrency wallet. The dataset therefore states that a named person at a specific address bought a device whose purpose is storing bearer assets, and that they did so recently enough to be worth visiting.

Hardware wallet owners have been targeted physically before, in robberies and kidnappings aimed at forcing a transfer. A home address paired with evidence of crypto holdings is a targeting list, and unlike a password it cannot be rotated.

The age of the records cuts both ways. A 2019 address is often stale, which reduces the risk for anyone who has moved. For anyone who has not, a seven-year-old record is exactly as actionable as a current one.

What a controller can actually do

Trezor's position looks defensible on the documents. It had a contract, a policy, repeated requests and written confirmations, which is more diligence than most controllers apply to a logistics vendor.

It was still not enough. Under most data protection regimes the controller remains accountable for what a processor does, and an assurance is evidence of effort rather than of deletion.

What would have closed it is verification: a deletion certificate tied to a specific record count and date, an audit right actually exercised, or a design that never gives the processor the data in the first place — order numbers rather than product names, a forwarding address rather than the customer's own.

Advertisement

The pattern this belongs to

Neither breach here happened at Trezor. Both happened at a fulfilment provider holding data on Trezor's behalf, which is where a growing share of consumer data incidents now originate.

This is structural. A company can harden its own systems and still be exposed through every processor it uses — logistics, payments, email, support — and each of those holds a slice of the same customer records under a contract rather than under direct control.

Shipping providers are a particularly poor place for this data to age. Their commercial purpose ends when the parcel arrives, they have no reason to retain anything afterwards, and they are not usually staffed or audited like a firm that expects to be attacked for what it holds.

What affected customers should do

Nothing in this breach exposes wallet seeds, keys or funds, and no Trezor device is less secure than it was. Anyone contacted about a firmware update, a security check or a required recovery-phrase entry as a result of this should treat it as a phishing attempt, because the attackers now know exactly which product each person bought.

The physical dimension is the harder one and there is no clean advice for it. Anyone at an address in the 2019 to 2021 set who still lives there and still holds significant assets should think about who knows, which is an uncomfortable thing to be told and more useful than a password reset.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement