🔐
Security 📅 2026-09-06 · 07:51 AM IST ⏱ 3 min read

Trezor Customers Discover Personal Information Wasn't Actually Deleted in Third-Party Breach

67,000 U.S. Trezor users affected after shipping partner's security failure exposed data supposedly removed.

A Deleted File That Wasn't Really Gone

Cryptocurrency wallet company Trezor has informed approximately 67,000 American customers that their personal information became public through a security incident at ShipMonk, a logistics company Trezor uses to deliver products. The troubling part of this story is that Trezor had previously assured customers their data had been permanently erased from ShipMonk's systems. That assurance turned out to be incorrect.

When customers place orders with Trezor, they provide names, addresses, phone numbers, and email addresses so the company can ship hardware wallets to them. Trezor said it had requested that ShipMonk delete this customer information after orders were completed and delivered. However, when ShipMonk experienced a data breach, investigators discovered the information was still sitting in ShipMonk's databases, exposed and vulnerable to theft.

What This Means

Think of it like asking your bank to shred your old statements after you've reviewed them, only to discover years later that they never actually destroyed them—and someone broke into their storage room and photographed everything. The information shouldn't have been there in the first place.

This incident reveals a gap in how companies verify that third-party service providers actually follow through on data deletion requests. Trezor trusted ShipMonk to handle the cleanup, but no one apparently verified that it actually happened. This is common in business relationships, but increasingly risky as companies collect more personal data.

The exposed information didn't include password-protected account credentials or cryptocurrency holdings, which would be far more catastrophic. However, the combination of name, address, phone, and email creates a complete profile that scammers and identity thieves find valuable.

Why You Should Care

If you ordered a Trezor device and live in the United States, your shipping address is now known to whoever accessed ShipMonk's systems. This makes you a target for several types of fraud. Criminals might attempt to:

The situation is particularly concerning because Trezor customers are known to hold valuable digital assets, making them attractive targets for sophisticated criminals.

What You Can Do

Start by assuming your information is compromised and take protective steps. Monitor your credit reports through free services and consider placing a fraud alert with credit bureaus. Watch for suspicious emails and calls, especially anything requesting verification of your identity or account details—legitimate companies rarely ask for this information through unsolicited contact.

Change passwords for any accounts using email addresses or phone numbers associated with your Trezor purchase. Be extra cautious about any communications claiming to involve your cryptocurrency accounts or delivery services. Consider using unique, complex passwords for different accounts so that if one gets exposed, others remain protected.

This breach is a reminder that companies should regularly audit whether third-party vendors are actually following data protection agreements, rather than simply trusting their word.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →