Reading view

There are new articles available, click to refresh the page.

Trezor Reveals Another Data Breach After Scammers Target Marketing Platform 

Bitcoin Magazine

Trezor Reveals Another Data Breach After Scammers Target Marketing Platform 

Trezor has warned that a data breach at the third-party marketing platform it uses for sending newsletters is leading criminals to target customers with phishing attacks. 

The top hardware wallet manufacturer said Wednesday that an unauthorized actor got access to Brevo’s system and sent emails to 347,000 Trezor customers. Brevo is a platform businesses use to send customer communications. 

Scammers managed to use Trezor’s domain name to send the email, making the phishing attempt all the more believable. The email contained a malicious link asking users to download an app and enter their wallet backup. 

Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.

We have taken down the domain, and we are investigating…

— Trezor (@Trezor) September 9, 2026

The news comes after Trezor last month announced that data from 11,742 customers had been exposed after its third-party fulfillment partner, ShipMonk, was targeted. 

It then said last week that an additional 67,000 U.S. customers had their names, emails, phone numbers, shipping addresses and order numbers leaked in the breach. 

“We took down the domain at the DNS level within 20 minutes, preventing the link from working for anyone else and limiting access to 2,500 people who had clicked it before we took it down,” Trezor said on Wednesday. 

“These addresses might be potentially used for other phishing attacks in the future. No other Trezor system was touched,” Trezor added.

“We have suspended the Brevo account to stop further email distribution.”

Trezor reminded users that it never asks customers to ask for their wallet backups. 

Criminals have been targeting data this year, with scammers getting hold of customer information via crypto wallet Ledger’s payment processor Global-e to send phishing emails. 

Crypto wallet provider SafePal last month also announced a data breach that involved ​unauthorized access to about 39,798 customers’ order information, ‌including personal details such as names, addresses and purchase data.

This post Trezor Reveals Another Data Breach After Scammers Target Marketing Platform  first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

Trezor Breach Worse Than Reported: Another 67,000 US Customers Exposed

Bitcoin Magazine

Trezor Breach Worse Than Reported: Another 67,000 US Customers Exposed

Hardware wallet manufacturer Trezor has said that a data breach first announced last month is worse than originally reported. 

The Prague, Czech Republic-based company said Friday that an additional 67,000 U.S. customers had their names, emails, phone numbers, shipping addresses and order numbers leaked. The leaked data came from orders made between November 2019 and August 2021, according to Trezor. 

Trezor first announced in August that data from 11,742 customers from the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal had been exposed — with names, emails, phone numbers and shipping addresses leaked. 

Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought.

Another 67,000 customers from the US who ordered between November 2019 and August 2021… https://t.co/yDQvTlAA2S

— Trezor (@Trezor) September 4, 2026

Another 1,947 customers just had their names, cities and emails exposed in the breach. 

In Friday’s announcement, Trezor said that its third-party fulfillment partner, ShipMonk, had falsely reassured the company about deleting customer data. 

In a statement to Bitcoin Magazine, a Trezor spokesperson said: “We had no reason to expect it: throughout our entire relationship with ShipMonk we repeatedly requested and received written assurance confirming the deletion of that data, in line with our contract, our data policy and our past communications.”

“It should not have existed to be exposed,” the statement added.

ShipMonk did not immediately responded to Bitcoin Magazine’s questions. 

Trezor first announced in August that the data had been leaked because ShipMonk experienced “unauthorized access to their systems containing customer data.” 

The company added that it had directly emailed all customers involved in the breach. Trezor’s parent company, SatoshiLabs, told Bitcoin Magazine last month that it was investigating the incident. 

Trezor is one of the most popular Bitcoin hardware wallet solutions, and also has support for storing other cryptocurrencies. 

Bitcoiners’ personal data has been targeted by cybercriminals in the past: back in 2020, an unauthorized party accessed popular hardware manufacturer Ledger’s e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers. 

At the start of this year, customers reported receiving emails from Global-e, Ledger’s payment partner, that a data breach at its cloud systems leaked sensitive customer data. 

This piece has been updated to include additional commentary from Trezor.

This post Trezor Breach Worse Than Reported: Another 67,000 US Customers Exposed first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

Data Breach at Trezor Leaks Info on Nearly 14,000 Bitcoin Wallet Users

Bitcoin Magazine

Data Breach at Trezor Leaks Info on Nearly 14,000 Bitcoin Wallet Users

Hardware wallet manufacturer Trezor has announced a data breach exposing customer data. 

Writing on X Thursday, the company said that 13,689 customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order 90 days prior to August 8 were affected. 

We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…

— Trezor (@Trezor) August 13, 2026

“Our systems and devices remain secure, but affected customers could experience an increase in phishing attempts,” the Prague, Czech Republic-based company said. “We are deeply sorry to the community and those affected.”

Trezor said that 11,742 customers had their names, emails, phone numbers, and shipping addresses leaked. Another 1,947 customers had just their names, cities and emails exposed. 

SatoshiLabs, the parent company of Trezor, said in an email to Bitcoin Magazine that its third-party fulfillment partner, ShipMonk, had experienced “unauthorized access to their systems containing customer data.”

“Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor,” the company said. 

SatoshiLabs said it was continuing to investigate the incident. 

Trezor is one of the most popular Bitcoin hardware wallet solutions, and also has support for storing other cryptocurrencies. 

Bitcoiners’ personal data has been targeted by cybercriminals in the past: back in 2020, an unauthorized party accessed popular hardware manufacturer Ledger’s e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers. 

And at the start of this year, customers reported receiving emails from Global-e, Ledger’s payment partner, that a data breach at its cloud systems leaked sensitive customer data. 

The Bitcoin community is still reeling after hackers targeted Canadian company Coinkite’s popular Coldcard product. 

Hackers started draining $111 million in Bitcoin from the popular Coldcard hardware wallets at the end of last month.The amount stolen could be much higher as investigations continue, with some estimating the real figure to be over $130 million. 

The theft continued, with Bitcoiners — and Coinkite — asking users to move their funds as hackers continued to drain digital coins from the later devices. 

This post Data Breach at Trezor Leaks Info on Nearly 14,000 Bitcoin Wallet Users first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

❌