# Trezor Data Breach Investigation - Hall Attorneys, P.C. Canonical overview: https://hallattorneys.com/investigations/trezor Published: September 4, 2026 Last reviewed: September 9, 2026 ## Investigation status Hall Attorneys is evaluating potential claims. This is an investigation, not a filed lawsuit by Hall Attorneys. ## Summary Hall Attorneys is investigating Trezor-related data exposure and phishing. In a September 9, 2026 statement shown in the source screenshot, Trezor reported a breach of its third-party email provider and warned that an email titled 'Critical Security Alert: STM32 Entropy Vulnerability' was a phishing attempt. This update also covers the earlier ShipMonk order-data breach. A connection between the two events has not been established. ## Facts and scope - September 9: Trezor's statement says its third-party email provider was breached and warns recipients not to click links in the fraudulent security-alert email. - The statement says a domain was taken down and an investigation was underway into how attackers accessed Trezor's legitimate domain. It does not identify the provider, affected-person count, or full data scope. - The approximately 67,000 additional U.S. customers disclosed September 4 concern ShipMonk order records. That number is not a count of people affected by the email-provider incident. ## What happened? September 9 email-provider update: In the @Trezor statement reproduced in the source screenshot, Trezor says its third-party email provider was breached. It identifies the email titled 'Critical Security Alert: STM32 Entropy Vulnerability' as phishing, says the message did not come from Trezor, and tells recipients not to click its links. Trezor says it took down a domain and was investigating the situation, including how attackers gained access to its legitimate domain. The statement does not name the email provider, quantify affected recipients, specify all data accessed, or establish a connection to ShipMonk. The email's vulnerability claim is part of the phishing lure; this warning does not establish an actual STM32 flaw in Trezor devices. Trezor says ShipMonk, one of its shipping providers, informed it on August 10, 2026 of unauthorized access to systems containing customer order data. Trezor's August 13 notice initially identified 11,742 customers with full exposure and 1,947 customers with partial exposure. On September 4, Trezor disclosed that ShipMonk had provided a further update two days earlier. According to Trezor, approximately 67,000 additional U.S. customers who ordered between November 2019 and August 2021 had names, email addresses, phone numbers, shipping addresses, and order numbers exposed. Trezor says it had repeatedly requested and received written assurances that older order data was deleted in accordance with its contract and data policy, but later learned the records remained in ShipMonk's systems. The public record reviewed for this page does not yet establish why the data remained, the precise unauthorized-access period, or whether the reported counts contain any overlap. For the ShipMonk incident, Trezor says its systems, products, and devices were not compromised. The reported order data does not include wallet backups or recovery seeds. That earlier assurance should not be treated as a complete assessment of the September 9 email-provider incident. Contact information tied to a hardware-wallet purchase may support highly tailored phishing, impersonation, fraudulent letters, or physical-security threats. ## Timeline - November 2019–August 2021: Older U.S. order records retained. Trezor says the approximately 67,000 additional customers placed orders during this period and that ShipMonk retained records Trezor understood had been deleted. - August 10, 2026: ShipMonk notifies Trezor. Trezor says its shipping provider reported unauthorized access to systems containing customer data. - August 13, 2026: Trezor publishes its initial notice. Trezor initially reported 11,742 customers with full exposure and 1,947 with partial exposure, or approximately 13,689 customers in total. - September 2, 2026: ShipMonk reports a broader scope. Trezor says ShipMonk informed it that older U.S. order records were also involved in the incident. - September 4, 2026: Approximately 67,000 more customers disclosed. Trezor publicly announced the additional U.S. customer group and said all newly affected customers had been emailed directly. - September 9, 2026: Email-provider breach and phishing warning. The @Trezor statement shown in the source screenshot reports a third-party email-provider breach, identifies the STM32 security-alert email as phishing, and says a domain was taken down while the investigation continued. The scope and any relationship to ShipMonk remain unestablished. ## Data involved The September 9 email-provider statement does not specify the full data accessed or the number of people affected. The categories below refer to the earlier ShipMonk fulfillment and order records, which can reveal how to contact a customer and where a hardware wallet was delivered. - Identity information: Customer names - Contact information: Email addresses and phone numbers - Delivery information: Shipping addresses associated with Trezor orders - Transaction context: Order numbers and an apparent connection to a Trezor purchase For ShipMonk, Trezor says its systems and devices were not compromised, and the reported exposed fields do not include recovery seeds or private keys. The September 9 warning does not establish a device vulnerability or theft of wallet keys; it also does not provide a complete forensic assessment of the email-provider breach. ## Who may be affected? People who received the September 9 phishing email may wish to preserve it and document any resulting harm. The email-provider statement does not define a complete affected group. Separately, the September 4 ShipMonk expansion covers approximately 67,000 U.S. customers with orders from November 2019 through August 2021, in addition to the initial group in seven countries. ## Records to preserve Preserve enough information to document the affected transaction and any resulting harm, but do not send wallet credentials, a recovery seed, cryptocurrency holdings, passwords, or complete financial-account information through an ordinary contact form. - Trezor notices and updates: Keep the complete incident email, its headers, any envelope, the date received, and later updates. Save a copy before deleting or reporting a suspicious message. - Order and delivery records: Preserve the invoice, order confirmation, order number, seller, shipping notices, tracking history, delivery country, and address used at the time. - Proof of the fulfillment provider: Save labels, return instructions, tracking pages, or support messages that identify ShipMonk or another shipping provider associated with the order. - Suspicious digital communications: Keep wallet-themed emails, texts, caller details, fake support messages, account alerts, and screenshots of websites or profiles used in an impersonation attempt. - Physical mail or threats: Preserve fraudulent letters and envelopes and document any threat. Contact local emergency services if there is an immediate safety concern. - Time, expense, and loss: Maintain a dated log of time spent securing accounts, professional or security expenses, lost funds, replacement costs, and other concrete effects. ## Frequently asked questions ### What did Trezor report on September 9, 2026? In the @Trezor statement shown in the supplied source screenshot, Trezor reports a breach of its third-party email provider and warns about a phishing email titled 'Critical Security Alert: STM32 Entropy Vulnerability'. It says a domain was taken down and the investigation was ongoing. The original post URL was not independently verified during this review. ### Is the STM32 Entropy Vulnerability email from Trezor legitimate? Trezor's September 9 statement identifies that email as phishing and says it did not come from Trezor. Do not click its links, download its attachments, or enter a recovery seed or wallet backup. The message is not evidence of a confirmed STM32 vulnerability in Trezor devices. ### Is the email-provider breach the same as the ShipMonk breach? A connection has not been established. The September 9 statement concerns an email provider; the earlier ShipMonk notices concern shipping and order records. The approximately 67,000 additional U.S. customers and approximately 80,689 conditional total refer to ShipMonk, not the email-provider incident. The September 9 statement does not give an affected-person count. ### What should I do if I received or clicked the phishing email? Stop interacting with the message and preserve the original email, headers, received time, and any evidence of what you clicked or disclosed. Navigate independently to trezor.io/support for official assistance. If you entered a recovery seed, wallet backup, or other secret, seek official support promptly and explain what happened without sending the secret itself. Keep records of suspicious transactions, expenses, and losses. ### How many Trezor customers were affected by ShipMonk? Trezor initially reported approximately 13,689 affected customers. On September 4, 2026, it said approximately 67,000 additional U.S. customers were affected, bringing the reported total to approximately 80,689 if the groups do not overlap. ### Which Trezor orders are included in the September 4 ShipMonk disclosure? Trezor says the newly disclosed group consists of U.S. customers who ordered between November 2019 and August 2021. Its August notice concerned a separate recent-order group in the United States and six other countries. ### What information was exposed in the ShipMonk breach? Trezor says the newly identified records contained names, email addresses, phone numbers, shipping addresses, and order numbers. ### Were Trezor devices, private keys, or recovery seeds compromised? For the ShipMonk breach, Trezor says its own systems and devices were not compromised and the reported fields do not include private keys or recovery seeds. The September 9 email-provider warning does not establish that devices or wallet keys were compromised, but it does not provide a complete forensic assessment. Never enter wallet secrets into a site reached through an email. ### How can I tell whether I was affected? For ShipMonk, Trezor says it emailed affected customers directly. Verify notices through Trezor's official website and preserve your order records. For the September 9 event, keep the suspicious email if received, but do not treat it as proof of ShipMonk exposure. No complete affected-person list for the email-provider incident is established in the statement reviewed here. ### What should an affected customer avoid sharing? Never share a wallet backup, recovery seed, PIN, passphrase, password, remote device access, or cryptocurrency balance with someone who contacts you. Trezor says it will never ask for a wallet backup. ### Has Hall Attorneys filed a Trezor or ShipMonk lawsuit? No. This page describes an investigation by Hall Attorneys and does not state that the firm has filed a lawsuit concerning Trezor or ShipMonk. ## Sources and attribution The September 9 update relies on the supplied screenshot of a statement attributed to Trezor's @Trezor account on X. The original post URL was not available for independent verification during this review. The screenshot is linked below as a source alongside the earlier ShipMonk notice and reporting; it does not establish the email-provider incident's full scope. - Trezor (@Trezor on X; supplied screenshot), September 9, 2026: September 9 email-provider breach warning (source screenshot) https://hallattorneys.com/images/trezor-email-provider-warning-2026-09-09.png The supplied screenshot shows a September 9 @Trezor statement reporting an email-provider breach, identifying the STM32 security-alert email as phishing, and describing a domain takedown and ongoing investigation. - CyberInsider, September 4, 2026: Trezor Says Data of Another 67,000 US Customers Exposed in Breach https://cyberinsider.com/trezor-says-data-of-another-67000-us-customers-exposed-in-breach/ Reports Trezor's expanded disclosure, the older U.S. order window, the customer information involved, and Trezor's statements concerning data deletion and device security. - Trezor, August 13, 2026: Recent customer data exposed in shipping provider incident https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident Trezor's initial incident notice identifies ShipMonk, the first reported customer groups, exposed data categories, notification process, and wallet-safety guidance. - The Block, September 4, 2026: Trezor says ShipMonk breach affected another 67,000 customers https://www.theblock.co/news/business/2026-09-04-trezor-says-shipmonk-breach-affected-another-67000-customers-413540 Contemporaneous reporting on the additional U.S. customers, 2019–2021 order records, exposed fields, and Trezor's September 4 statement. - Federal Trade Commission, Accessed September 4, 2026: How To Recognize and Avoid Phishing Scams https://consumer.ftc.gov/articles/how-recognize-and-avoid-phishing-scams Official consumer guidance for recognizing, reporting, and responding to phishing messages. ## Contact Tell Hall Attorneys when you received the suspicious email or breach notice, whether you clicked a link or disclosed information, and any resulting expense or loss. For ShipMonk, include your order date and country. Do not send a recovery seed, wallet backup, PIN, passphrase, password, cryptocurrency balance, or complete financial record in an initial message. Nicholas Hall Hall Attorneys, P.C. nhall@hallattorneys.com +1 713 428 8967 https://hallattorneys.com/connect Attorney advertising. Sending information does not create an attorney-client relationship.