Trezor notices and updates
Keep the complete incident email, its headers, any envelope, the date received, and later updates. Save a copy before deleting or reporting a suspicious message.
Hall Attorneys is evaluating potential claims after Trezor said a breach at shipping provider ShipMonk exposed customer order data. The latest disclosure adds approximately 67,000 U.S. customers who ordered between November 2019 and August 2021. Trezor says its systems and devices were not compromised, but the exposed contact and delivery information may enable convincing scams and other targeted threats.
latest scope disclosed September 4, 2026
67,000 additional plus 13,689 initially reported
November 2019 through August 2021
Could this be me?
The clearest indicator is a direct notification from Trezor. Order timing and fulfillment records can also help identify a possible connection, particularly for U.S. customers who ordered between November 2019 and August 2021 or customers included in Trezor's August notice.
Preserve the complete message, its headers, and any follow-up. Verify the sender and navigate to Trezor's official website independently rather than using an unexpected link or phone number.
The latest disclosure concerns approximately 67,000 U.S. customers whose orders date from November 2019 through August 2021. Save the order confirmation, invoice, delivery record, and the address used at the time.
Trezor's initial notice covered recent orders delivered in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The company initially reported 11,742 fully exposed and 1,947 partially exposed customers.
Check shipping notices, tracking pages, labels, return records, support messages, and delivery updates for ShipMonk or another fulfillment-provider reference tied to the Trezor order.
A purchase from Amazon or another independent retailer does not necessarily appear in Trezor's direct-order data. Preserve the receipt and identify the actual seller and shipper before assuming a connection.
Keep the communication, envelope, caller information, and any related account alerts. Do not share a wallet backup, recovery seed, PIN, passphrase, password, or remote access to a device.
Check your records
Search your own records for the company and fulfillment names. Use official Trezor channels to verify a notice, and never enter a wallet backup into a website or disclose it to someone contacting you.
Answer at a glance
Trezor says ShipMonk, one of its shipping providers, informed it on August 10, 2026 of unauthorized access to systems containing customer order data. Trezor's August 13 notice initially identified 11,742 customers with full exposure and 1,947 customers with partial exposure.
On September 4, Trezor disclosed that ShipMonk had provided a further update two days earlier. According to Trezor, approximately 67,000 additional U.S. customers who ordered between November 2019 and August 2021 had names, email addresses, phone numbers, shipping addresses, and order numbers exposed.
Trezor says it had repeatedly requested and received written assurances that older order data was deleted in accordance with its contract and data policy, but later learned the records remained in ShipMonk's systems. The public record reviewed for this page does not yet establish why the data remained, the precise unauthorized-access period, or whether the reported counts contain any overlap.
Trezor says its systems, products, and devices were not compromised. The reported data does not include wallet backups or recovery seeds, but contact information tied to a hardware-wallet purchase may support highly tailored phishing, impersonation, fraudulent letters, or physical-security threats.
This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.
Trezor says the approximately 67,000 additional customers placed orders during this period and that ShipMonk retained records Trezor understood had been deleted.
Trezor says its shipping provider reported unauthorized access to systems containing customer data.
Trezor initially reported 11,742 customers with full exposure and 1,947 with partial exposure, or approximately 13,689 customers in total.
Trezor says ShipMonk informed it that older U.S. order records were also involved in the incident.
Trezor publicly announced the additional U.S. customer group and said all newly affected customers had been emailed directly.
Reported data categories
Trezor describes the exposed information as fulfillment and order data held by ShipMonk. The combination can reveal both how to contact a customer and where a hardware wallet was delivered.
Important distinction
Trezor says its own systems and devices were not compromised. Public reporting reviewed for this page does not identify wallet backups, recovery seeds, private keys, wallet balances, passwords, or payment-card numbers as exposed data.
Who may want to contact us
The latest group consists of approximately 67,000 U.S. customers who ordered between November 2019 and August 2021. Trezor's initial disclosure also covered recent customers in seven countries. A direct Trezor notice is the strongest public indicator of inclusion.
U.S. customers who ordered directly from Trezor between November 2019 and August 2021 and received an incident notice
Customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal included in Trezor's August 2026 notice
People whose current or former home address was associated with an affected Trezor order
Affected customers who receive targeted wallet-themed phishing, fraudulent calls or letters, impersonation attempts, or physical threats
People who spend time or money responding to misuse connected to the exposed order information
What to preserve
Preserve enough information to document the affected transaction and any resulting harm, but do not send wallet credentials, a recovery seed, cryptocurrency holdings, passwords, or complete financial-account information through an ordinary contact form.
Keep the complete incident email, its headers, any envelope, the date received, and later updates. Save a copy before deleting or reporting a suspicious message.
Preserve the invoice, order confirmation, order number, seller, shipping notices, tracking history, delivery country, and address used at the time.
Save labels, return instructions, tracking pages, or support messages that identify ShipMonk or another shipping provider associated with the order.
Keep wallet-themed emails, texts, caller details, fake support messages, account alerts, and screenshots of websites or profiles used in an impersonation attempt.
Preserve fraudulent letters and envelopes and document any threat. Contact local emergency services if there is an immediate safety concern.
Maintain a dated log of time spent securing accounts, professional or security expenses, lost funds, replacement costs, and other concrete effects.
Investigation focus
Hall Attorneys is reviewing the unauthorized access, retention of older order data, notice and protective measures, and any phishing, fraud, physical-security concern, expense, or other harm experienced by affected customers.
Public records reviewed
The sources below include Trezor's initial public notice and contemporaneous reporting on the September scope expansion. The investigation remains ongoing and the public account may change.
CyberInsider ·
Reports Trezor's expanded disclosure, the older U.S. order window, the customer information involved, and Trezor's statements concerning data deletion and device security.
Read source: Trezor Says Data of Another 67,000 US Customers Exposed in BreachTrezor ·
Trezor's initial incident notice identifies ShipMonk, the first reported customer groups, exposed data categories, notification process, and wallet-safety guidance.
Read source: Recent customer data exposed in shipping provider incidentThe Block ·
Contemporaneous reporting on the additional U.S. customers, 2019–2021 order records, exposed fields, and Trezor's September 4 statement.
Read source: Trezor says ShipMonk breach affected another 67,000 customersFederal Trade Commission ·
Official consumer guidance for recognizing, reporting, and responding to phishing messages.
Read source: How To Recognize and Avoid Phishing ScamsContact the firm
Contact Hall Attorneys with your order date and country, whether you received Trezor's notice, whether the delivery address remains current, and a summary of suspicious contact, expense, or loss. Do not send a recovery seed, wallet backup, PIN, passphrase, password, cryptocurrency balance, or complete financial record in an initial message.
Frequently asked questions
Trezor initially reported approximately 13,689 affected customers. On September 4, 2026, it said approximately 67,000 additional U.S. customers were affected, bringing the reported total to approximately 80,689 if the groups do not overlap.
Trezor says the newly disclosed group consists of U.S. customers who ordered between November 2019 and August 2021. Its August notice concerned a separate recent-order group in the United States and six other countries.
Trezor says the newly identified records contained names, email addresses, phone numbers, shipping addresses, and order numbers.
Trezor says its own systems and devices were not compromised. The public sources reviewed for this page do not identify private keys, recovery seeds, wallet backups, PINs, passphrases, wallet balances, or payment-card numbers as exposed data.
Trezor says it emailed affected customers directly. Verify any message through Trezor's official website rather than an unexpected link, and preserve the notice and your order records. Owning a Trezor device alone does not prove inclusion.
Never share a wallet backup, recovery seed, PIN, passphrase, password, remote device access, or cryptocurrency balance with someone who contacts you. Trezor says it will never ask for a wallet backup.
No. This page describes an investigation by Hall Attorneys and does not state that the firm has filed a lawsuit concerning Trezor or ShipMonk.
Attorney Advertising
Hall Attorneys is not affiliated with Trezor or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.