Skip to content
CryptoCanucks

Search

Digital assets, blockchain, AI and cybersecurity, covered for Canada. Canada's first crypto newsroom, since Canada Day 2017.

A worried man in a grey hoodie with a red maple leaf holds a torn-open delivery box containing a small hardware wallet at his front door, under the words LEAKED?

CybersecurityNewsCrypto security in Canada →

Your wallet maker or exchange leaked your data: what Canadians can do

Trezor now says a shipping provider exposed the names, addresses and order details of about 80,000 customers, including records it had been assured were deleted. Ledger's 2020 leak shows what follows: phishing that knows your name, and letters at the door. Here is what Canadian law requires, and what to do this week.

Quick take

  1. 01Trezor says a breach at its shipping provider exposed names, addresses, phones and order details for 13,689 recent customers, then about 67,000 more from 2019 to 2021 in records it had been told were deleted. The devices and keys were not touched.
  2. 02The danger is what follows: Ledger's 2020 leak of about a million emails and 272,000 addresses was followed by years of phishing emails, texts, calls and letters at the door asking for the seed phrase.
  3. 03PIPEDA makes the company notify you and the Privacy Commissioner when there is a real risk of significant harm; your job this week is passwords, real MFA, treating every message about the order as an attack, and never typing the seed anywhere.

If you bought a hardware wallet from Trezor in the last few years, check the inbox you ordered with. On September 4, 2026 the company added a line to its breach notice that turns a contained incident into a large one: the data exposed at its shipping provider “also contained order data from our prior cooperation between November 2019 and August 2021,” records Trezor says it had been assured were deleted. That adds “approximately 67,000” customers to the 13,689 disclosed in August.

Nothing about your coins is in that data. What is in it is your name, your address, your phone number and the fact that you own a device built to hold crypto. For most retailers that is an ordinary leak. For a wallet maker it is a targeting list, and the last time one leaked, the targeting went on for years. This piece covers what happened, what Ledger’s 2020 leak taught everyone about what comes next, what Canadian law requires of the company, and what to do this week.

What Trezor says happened

The breach was at ShipMonk, the logistics company that ships Trezor’s orders, on August 10, 2026. Trezor’s first notice, on August 13, said it affected “11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure,” the latter meaning name, city and email without the street address, plus order numbers. “The contents of the parcel were not exposed,” it said, and “Trezor systems, hardware wallets, private keys, and wallet backups were not affected.”

The September 4 update is the part that stings. Trezor says it had “repeatedly requested and received written assurance confirming the deletion” of the older records.

Despite receiving this confirmation, the data was not deleted in their systems. Trezor, breach notice update, September 4, 2026

The company describes the older group as U.S. customers. The August group had no country limit. Trezor says all affected customers were emailed directly and that anyone who did not get that email is not affected, so the check is simple: look for the email, and confirm anything it asks against Trezor’s own blog rather than through a link. The notice itself acknowledges the leak “could potentially expose affected individuals to physical security risks.”

~80,700Trezor customers whose contact and order details were exposed, in two groupsTrezor, August 13 and September 4, 2026
272,000Ledger customers whose name, address and phone leaked in 2020, from a database of about a million emailsLedger CEO statement, December 21, 2020
170+Phishing websites Ledger took down in the months after its leakLedger, December 21, 2020
$100,000Maximum fine for knowingly failing to report a breach under PIPEDAPIPEDA section 28

What happens next: the Ledger precedent

In June 2020 a database at Ledger, the other large hardware-wallet maker, was accessed through an API key. Ledger disclosed it on July 29 as about a million email addresses plus detailed records for 9,500 customers. In December the full contents were posted to a hacking forum, and the company’s CEO revised the detailed figure to “approximately 272,000” names, addresses and phone numbers.

What followed is the reason to take a leaked address seriously. Ledger reported taking down “more than 170 phishing websites” within months. Its phishing tracker records fake emails, texts, phone calls, a look-alike domain with an accented letter, fake wallet software, and “physical letters in the mail” carrying QR codes that lead to a page asking for the 24-word seed. The company’s advice has not changed since: it “will never contact users via phone call, for any reason,” it will never ask for the seed, and users should “never pay any ransom” and, “if you fear for your physical safety,” contact the police. Ledger also made the point that matters most for peace of mind: “there is no way to make any correlation between the data that has leaked and the funds on your wallet.”

What Canadian law requires of the company

Since November 1, 2018, PIPEDA has required an organization to report a breach of security safeguards to the Privacy Commissioner and to notify the affected individuals “if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm.” The Act defines significant harm to include “financial loss, identity theft, negative effects on the credit record and damage to or loss of property,” and weighs “the sensitivity of the personal information” and “the probability that the personal information has been, is being or will be misused.” A name, address and proof of crypto ownership sits comfortably inside that test.

The regulations say the notice must include “steps that affected individuals could take to reduce the risk of harm,” delivered in person, by phone, mail, email or another reasonable channel, and that the organization must keep a record of every breach for 24 months. The Privacy Commissioner’s guidance is to notify “as soon as feasible.” Knowingly failing to report or keep records is an offence, with fines up to $10,000 on summary conviction and $100,000 on indictment.

Two points for anyone who assumes a foreign company is out of reach. The Commissioner has applied PIPEDA to companies with no Canadian office where there is “a real and substantial connection to Canada,” most prominently in the 2021 Clearview AI finding. And Quebec’s Law 25 goes further than the federal act: the province’s privacy regulator can impose administrative penalties up to 2 percent of global turnover or $10 million, and failing to declare an incident that carries a risk of serious harm is on the list of sanctionable conduct.

What to do this week

The regulators’ and the vendors’ advice overlaps almost completely. In order:

  1. Change the password on the account that leaked, and turn on real multi-factor authentication. The Cyber Centre says SMS codes “are sent in unencrypted form” and recommends hardware security keys. Do the same for the email address that was exposed.
  2. Treat every message about the order as an attack until proven otherwise. The Cyber Centre’s tells: an urgent tone, a push to act now, a link, an attachment or a QR code. Its instruction is “do not click the link, do not open attached files and avoid scanning QR codes.” Go to the company’s site by typing the address.
  3. Never type the seed phrase anywhere. Not into a site, an app, a support chat or a “verification” form. Trezor’s rule is that any request to enter the backup that you did not initiate on the device itself “is a scam.”
  4. Check addresses character by character when you send. Leaked order data helps scammers pick targets for address poisoning, where a look-alike address is planted in your history.
  5. Consider a fresh wallet. The leak cannot expose keys, but if you have ever typed the seed into anything, or you would rather nobody could connect the name on that list to a balance, move to a new device backup. Both makers say a backup that may have been seen means moving funds immediately.
  6. Put an alert on your credit file. Equifax’s Identity Alert is free and stays for six years; in Ontario and Manitoba it legally obliges lenders to call you before extending credit. Do the same at TransUnion.
  7. Report what happens. Phishing attempts and any loss go to the Canadian Anti-Fraud Centre at 1-888-495-8501, and to local police with a file number. Threats to your safety go to the police first.

Exchanges are not exempt

Wallet makers are retailers; exchanges hold far more. Under the CSA’s 2017 cybersecurity notice, registered firms must keep controls that “safeguard the confidentiality, integrity and availability of the firm’s data, including the personal information of clients,” plan in advance “what information should be reported” and to whom, and require vendors “to notify firms of cyber security incidents.” The same notice reported that about 51 percent of surveyed firms had experienced an incident in a year. Canada has had its own case: in November 2022 Coinsquare told customers that names, emails, addresses, phone numbers, dates of birth, wallet addresses, transaction history and balances had been exposed while passwords and cold-storage assets were not, according to the customer email quoted by Cointelegraph. The registration regime that followed a year later is described in the regulation hub.

Where the lawsuits stand

The one class action over a wallet-maker leak, Baton v. Ledger, was filed in California in April 2021. Most of it was dismissed because Ledger’s terms send disputes to French courts; an appeals court let California consumer claims proceed in 2022, Shopify was later dismissed, and as of the October 2025 status report a single claim against Ledger remains, with no settlement on the docket. As of September 6, 2026, no class action over the Trezor exposure appears on the U.S. court dockets or the class-action trackers. For a Canadian, the practical route is the one above: the company first, the Commissioner second, and the Federal Court if it comes to that.

Frequently asked

Was my Trezor device or my crypto compromised?

No, according to Trezor. It says the breach was at ShipMonk, its shipping provider, and that Trezor systems, hardware wallets, private keys and wallet backups were not affected. What leaked is who you are, where you live, and that you bought a hardware wallet.

Am I affected if I am in Canada?

Trezor says every affected customer was emailed directly and that anyone who did not receive that email is not affected. The first group of 13,689 customers covered orders from May 10 to August 8, 2026 without a country limit; the second group of about 67,000 from 2019 to 2021 is described as U.S. customers. Check the inbox you used to order, and check it against Trezor's blog rather than any link in a message.

What does Canadian law require of the company?

Under PIPEDA, an organization must report a breach of security safeguards to the Privacy Commissioner and notify affected individuals when it is reasonable to believe the breach creates a real risk of significant harm, as soon as feasible, and keep a record of every breach for 24 months. Knowingly failing to do so is an offence with fines up to $100,000. The Commissioner has applied PIPEDA to foreign companies with a real and substantial connection to Canada. In Quebec, Law 25 adds administrative penalties up to 2 percent of global turnover or $10 million.

Should I move my coins to a new wallet?

The leak cannot reveal your keys, and Ledger said after its own breach that leaked customer data cannot be correlated with funds on a wallet. Moving coins is a precaution against the harder case: if you ever entered your seed anywhere, or fear someone knows what you hold and where you live, a fresh wallet with a new backup removes both worries. If your backup may have been seen, both makers say to move funds immediately.

Can I sue or complain?

You can complain to the Office of the Privacy Commissioner after raising it with the company; the OPC can investigate and, after its report, you can apply to the Federal Court, which can award damages. A U.S. class action over Ledger's 2020 leak, filed in April 2021, is still open on one claim in California after most of it was dismissed for jurisdiction. As of September 6, 2026, no class action over the Trezor exposure appears on the U.S. dockets.

Sources

  1. Trezor: Recent customer data exposed in shipping provider incident · Numbers, what was and was not exposed, the deletion assurance, the advice. August 13, 2026, updated August 14 and September 4, 2026.
  2. Ledger: Addressing the July 2020 e-commerce and marketing data breach · About one million email addresses; 9,500 customers' details; CNIL notified. July 29, 2020.
  3. Ledger: Message by Ledger's CEO, update on the July data breach · The December 2020 dump; about 272,000 detailed records; no correlation with funds. December 21, 2020.
  4. Ledger: Our communications about the data breach and the phishing attempts · More than 170 phishing sites taken down; only 40 percent opened the first notice. December 21, 2020.
  5. Ledger: Ongoing phishing campaigns · Physical letters with QR codes; Ledger never calls. Examples to January 2026.
  6. Ledger: 6 ways to face the data breach · Never pay a ransom; contact local authorities if you fear for your safety. December 22, 2020.
  7. Personal Information Protection and Electronic Documents Act, sections 10.1 to 10.3, 11, 14, 16 and 28 · Breach reporting, the real-risk-of-significant-harm test, complaints, Federal Court remedies, offences.
  8. Breach of Security Safeguards Regulations, SOR/2018-64 · What a notice must contain; records kept 24 months. In force November 1, 2018.
  9. Office of the Privacy Commissioner: What you need to know about mandatory reporting of breaches of security safeguards · Notify as soon as feasible. Modified August 11, 2025.
  10. Office of the Privacy Commissioner: What to do when you receive a privacy breach notification · What the notice must tell you and the steps to take. Modified July 4, 2025.
  11. Office of the Privacy Commissioner: File a complaint about a business · Raise it with the organization first; the OPC cannot force outcomes; Federal Court route.
  12. Office of the Privacy Commissioner: PIPEDA Findings #2021-001 (Clearview AI) · PIPEDA applies to a foreign company with a real and substantial connection to Canada. February 2, 2021.
  13. Commission d'accès à l'information du Québec: Sanctions et poursuites · Administrative penalties up to 2 percent of global turnover or $10 million; penal fines up to 4 percent or $25 million.
  14. Canadian Anti-Fraud Centre: What to do if you're a victim of fraud · Both credit bureaus, local police file number, change all passwords, 1-888-495-8501. Modified January 16, 2026.
  15. Canadian Centre for Cyber Security: Spotting malicious email messages (ITSAP.00.100) · Urgent tone; do not click, open or scan. January 2026.
  16. Canadian Centre for Cyber Security: Steps for effectively deploying multi-factor authentication (ITSAP.00.105) · SMS codes are sent unencrypted; hardware keys strongly recommended. May 2023.
  17. Equifax Canada: How can I place a fraud alert on my Equifax credit report? · Identity Alert is free and stays six years; lenders must call you in Ontario and Manitoba.
  18. Trezor support: What are address poisoning attacks and how to avoid them · Vanity look-alike addresses; check every character; avoid copying from history.
  19. CSA Staff Notice 33-321: Cyber Security and Social Media · Registered firms must safeguard client data and plan who to notify; 51 percent of surveyed firms had an incident. October 19, 2017.
  20. Cointelegraph: IIROC-registered Canadian crypto exchange Coinsquare suffers data breach · Secondary source quoting Coinsquare's customer email. November 26, 2022.
  21. Baton v. Ledger SAS, U.S. District Court, N.D. California, 3:21-cv-02470 (CourtListener docket) · Filed April 6, 2021; largely dismissed on jurisdiction; one California claim remains as of the October 2025 status report.
  • cybersecurity
  • data-breach
  • trezor
  • ledger
  • pipeda
  • privacy
  • phishing
  • hardware-wallet