Excerpt from Bloomberg, Published on September 4, 2026

Trezor, the Prague-based hardware crypto wallet maker, said a data breach at one of its shipping providers exposed the personal information of another 67,000 U.S. customers, significantly expanding the scope of an incident first disclosed in August.

The affected customers placed orders between November 2019 and August 2021. Trezor said their names, email addresses, phone numbers, and shipping addresses were exposed. The company previously reported that about 13,700 customers had been affected.

Trezor said the data breach occurred at shipping provider ShipMonk and did not compromise its own systems or devices. The company stated that no wallet backup, private key, or device was involved. It also said it had contacted all customers affected by the latest disclosure.

Trezor warned customers to remain alert for fraudulent emails, phone calls, letters, and potential physical-security risks. Exposed contact and address information could increase the risk of targeted social engineering or physical threats, although the reported breach does not indicate that cryptocurrency holdings or private keys were accessed.

The incident highlights the risks organizations face when third-party providers handle customer information. Vendor oversight should include understanding what data suppliers retain, how they protect it, and how quickly they can report security incidents.

Organizations should also ensure their incident-response plans address breaches involving service providers and support timely communication with affected individuals.

For additional information, visit Bloomberg.

Schedule A Meeting