Crypto wallet maker Trezor confirms 13,000 customers' details exposed in logistics breach
- ID
- 14145
- Status
- summarized
- Published
- 14 Aug 2026, 6:29 PM
- Fetched
- 14 Aug 2026, 7:22 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/14/crypto-wallet-maker-trezor-confirms-13000-customers-details-exposed-in-logistics-breach/5287734
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 14 Aug 2026, 7:23 PM
- Tags
- Audience
- saas-startup-founders
What happened
Trezor confirmed that a breach at its logistics partner ShipMonk exposed personal data of over 13,000 customers who ordered hardware wallets between May 10 and August 8, including names, email addresses, phone numbers, and shipping addresses across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. ShipMonk was subject to Trezor's 90-day data retention policy, but earlier orders may also be affected, and Trezor warned affected customers to expect increased phishing attempts.
Why it matters
If your SaaS or startup uses third-party logistics or fulfillment partners that handle customer PII, this is a concrete reminder that your vendor retention policies are only as good as your vendor's enforcement. The breach specifically shows that even a 90-day retention clause did not prevent earlier-order data from being exposed, meaning founders shipping physical products should audit whether partners actually delete or anonymize data on schedule rather than assuming contractual terms are followed.
Discussion angle
How to verify that logistics and fulfillment partners actually comply with data retention and deletion policies rather than just signing contracts that say they will.