Trezor Breach: The Data a Vendor Promised to Delete Leaked Anyway
A Trezor shipping vendor leaked ~67,000 US customers' home addresses from orders it was required to delete years ago. Why 'deleted' isn't a guarantee.
"We deleted it." They didn't — and it leaked.
This one should bother anyone who has ever been told their data was erased. Trezor has confirmed that a shipping partner, ShipMonk, exposed the names, phone numbers, and home addresses of about 67,000 US customers — from orders placed between 2019 and 2021. Data that, under Trezor's own contract, should have been deleted years ago.
According to Trezor, it repeatedly asked for — and received — written confirmation that the old records were gone. They weren't. They sat in the vendor's system until a breach spilled them.
The quiet failure mode of privacy
"Deleted" is a promise, not a guarantee. Every company that ever had your address is a company that might still have it — and might still leak it, long after you've forgotten you were ever a customer.
You can't force a vendor to keep its word, and you can't personally verify that thousands of companies actually purge old records. What you can do is make sure the address they're sitting on isn't also being actively published and resold everywhere else.
What you can do
- Reduce your live footprint. The fewer places your current address is listed, the less any single stale record matters.
- Get on the front foot with brokers. People-search sites publish and resell exactly this kind of leaked contact data — removal is a legal right, but it takes persistence.
- Keep it removed. Brokers repopulate; monitoring is the part that actually protects you over time.
GhostMyData finds where your information is being sold, removes it, and keeps it removed — automatically. Run a free scan to see your current exposure.
Sources: The Hacker News, BleepingComputer, CoinDesk, Trezor.
Want Us to Handle This for You?
You don't have to do this by hand. Start with a free scan and we'll remove your data from the broker network for you — and keep it gone.
Start Your Free ScanGet Privacy Tips in Your Inbox
Practical privacy tips to protect your personal data. No spam — unsubscribe anytime.
Related Articles
Carnival Data Breach: 6 Million Travelers' IDs Exposed
Carnival confirmed a breach exposing ~6 million travelers' names, addresses, DOB, driver's license and passport numbers via a social-engineered employee.
AdaptHealth Breach Exposes 4.1 Million: The Vendor Problem
AdaptHealth confirmed a breach of 4.1M patients through a social-engineered contractor. What was taken (no SSNs), and how to shrink your own exposure.
DentaQuest Data Breach Hits 15 Million: What Was Exposed
DentaQuest is notifying 15 million+ people after a breach exposed names, addresses, SSNs, and Medicaid/Medicare numbers. Here's how to limit the damage.