If you bought a hardware wallet from Trezor in the last few years, check the inbox you ordered with. On September 4, 2026 the company added a line to its breach notice that turns a contained incident into a large one: the data exposed at its shipping provider “also contained order data from our prior cooperation between November 2019 and August 2021,” records Trezor says it had been assured were deleted. That adds “approximately 67,000” customers to the 13,689 disclosed in August.
Nothing about your coins is in that data. What is in it is your name, your address, your phone number and the fact that you own a device built to hold crypto. For most retailers that is an ordinary leak. For a wallet maker it is a targeting list, and the last time one leaked, the targeting went on for years. This piece covers what happened, what Ledger’s 2020 leak taught everyone about what comes next, what Canadian law requires of the company, and what to do this week.
What Trezor says happened
The breach was at ShipMonk, the logistics company that ships Trezor’s orders, on August 10, 2026. Trezor’s first notice, on August 13, said it affected “11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure,” the latter meaning name, city and email without the street address, plus order numbers. “The contents of the parcel were not exposed,” it said, and “Trezor systems, hardware wallets, private keys, and wallet backups were not affected.”
The September 4 update is the part that stings. Trezor says it had “repeatedly requested and received written assurance confirming the deletion” of the older records.
Despite receiving this confirmation, the data was not deleted in their systems. Trezor, breach notice update, September 4, 2026
The company describes the older group as U.S. customers. The August group had no country limit. Trezor says all affected customers were emailed directly and that anyone who did not get that email is not affected, so the check is simple: look for the email, and confirm anything it asks against Trezor’s own blog rather than through a link. The notice itself acknowledges the leak “could potentially expose affected individuals to physical security risks.”
What happens next: the Ledger precedent
In June 2020 a database at Ledger, the other large hardware-wallet maker, was accessed through an API key. Ledger disclosed it on July 29 as about a million email addresses plus detailed records for 9,500 customers. In December the full contents were posted to a hacking forum, and the company’s CEO revised the detailed figure to “approximately 272,000” names, addresses and phone numbers.
What followed is the reason to take a leaked address seriously. Ledger reported taking down “more than 170 phishing websites” within months. Its phishing tracker records fake emails, texts, phone calls, a look-alike domain with an accented letter, fake wallet software, and “physical letters in the mail” carrying QR codes that lead to a page asking for the 24-word seed. The company’s advice has not changed since: it “will never contact users via phone call, for any reason,” it will never ask for the seed, and users should “never pay any ransom” and, “if you fear for your physical safety,” contact the police. Ledger also made the point that matters most for peace of mind: “there is no way to make any correlation between the data that has leaked and the funds on your wallet.”
What Canadian law requires of the company
Since November 1, 2018, PIPEDA has required an organization to report a breach of security safeguards to the Privacy Commissioner and to notify the affected individuals “if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm.” The Act defines significant harm to include “financial loss, identity theft, negative effects on the credit record and damage to or loss of property,” and weighs “the sensitivity of the personal information” and “the probability that the personal information has been, is being or will be misused.” A name, address and proof of crypto ownership sits comfortably inside that test.
The regulations say the notice must include “steps that affected individuals could take to reduce the risk of harm,” delivered in person, by phone, mail, email or another reasonable channel, and that the organization must keep a record of every breach for 24 months. The Privacy Commissioner’s guidance is to notify “as soon as feasible.” Knowingly failing to report or keep records is an offence, with fines up to $10,000 on summary conviction and $100,000 on indictment.
Two points for anyone who assumes a foreign company is out of reach. The Commissioner has applied PIPEDA to companies with no Canadian office where there is “a real and substantial connection to Canada,” most prominently in the 2021 Clearview AI finding. And Quebec’s Law 25 goes further than the federal act: the province’s privacy regulator can impose administrative penalties up to 2 percent of global turnover or $10 million, and failing to declare an incident that carries a risk of serious harm is on the list of sanctionable conduct.
What to do this week
The regulators’ and the vendors’ advice overlaps almost completely. In order:
- Change the password on the account that leaked, and turn on real multi-factor authentication. The Cyber Centre says SMS codes “are sent in unencrypted form” and recommends hardware security keys. Do the same for the email address that was exposed.
- Treat every message about the order as an attack until proven otherwise. The Cyber Centre’s tells: an urgent tone, a push to act now, a link, an attachment or a QR code. Its instruction is “do not click the link, do not open attached files and avoid scanning QR codes.” Go to the company’s site by typing the address.
- Never type the seed phrase anywhere. Not into a site, an app, a support chat or a “verification” form. Trezor’s rule is that any request to enter the backup that you did not initiate on the device itself “is a scam.”
- Check addresses character by character when you send. Leaked order data helps scammers pick targets for address poisoning, where a look-alike address is planted in your history.
- Consider a fresh wallet. The leak cannot expose keys, but if you have ever typed the seed into anything, or you would rather nobody could connect the name on that list to a balance, move to a new device backup. Both makers say a backup that may have been seen means moving funds immediately.
- Put an alert on your credit file. Equifax’s Identity Alert is free and stays for six years; in Ontario and Manitoba it legally obliges lenders to call you before extending credit. Do the same at TransUnion.
- Report what happens. Phishing attempts and any loss go to the Canadian Anti-Fraud Centre at 1-888-495-8501, and to local police with a file number. Threats to your safety go to the police first.
Exchanges are not exempt
Wallet makers are retailers; exchanges hold far more. Under the CSA’s 2017 cybersecurity notice, registered firms must keep controls that “safeguard the confidentiality, integrity and availability of the firm’s data, including the personal information of clients,” plan in advance “what information should be reported” and to whom, and require vendors “to notify firms of cyber security incidents.” The same notice reported that about 51 percent of surveyed firms had experienced an incident in a year. Canada has had its own case: in November 2022 Coinsquare told customers that names, emails, addresses, phone numbers, dates of birth, wallet addresses, transaction history and balances had been exposed while passwords and cold-storage assets were not, according to the customer email quoted by Cointelegraph. The registration regime that followed a year later is described in the regulation hub.
Where the lawsuits stand
The one class action over a wallet-maker leak, Baton v. Ledger, was filed in California in April 2021. Most of it was dismissed because Ledger’s terms send disputes to French courts; an appeals court let California consumer claims proceed in 2022, Shopify was later dismissed, and as of the October 2025 status report a single claim against Ledger remains, with no settlement on the docket. As of September 6, 2026, no class action over the Trezor exposure appears on the U.S. court dockets or the class-action trackers. For a Canadian, the practical route is the one above: the company first, the Commissioner second, and the Federal Court if it comes to that.
