{
  "story_id": "1d4e8bef55f02779f81294c78826b222",
  "desk": "drm3",
  "revision": 1,
  "published_at": "2026-09-04T20:30:14.000Z",
  "content_hash": "8ca9e7596c21eb2c8129522357281785dcef70f654469180091151614a68f2d1",
  "hash_basis": "sha256 over `headline\\ndek\\nprose`, plus `\\n` + the canonical citations JSON when any source is placed, plus `\\n#blog` for blogs",
  "basis": {
    "headline": "Trezor Data Breach Widens: 67,000 More U.S. Customers Exposed",
    "dek": "Trezor disclosed that 67,000 additional U.S. customers had their personal data exposed in a ShipMonk breach.",
    "prose": "Trezor announced on September 4, 2026, that an additional 67,000 U.S. customers had their data exposed in a breach at its shipping partner, ShipMonk. [^1]\n\nTrezor, a Prague-based hardware wallet manufacturer, said on 2026-09-04 that an additional 67,000 US customers had their names, emails, phone numbers, shipping addresses and order numbers leaked in a data breach. [^2]\n\nThe exposed records cover orders placed between November 2019 and August 2021 and include names, phone numbers, and home addresses. [^3]\n\nTrezor confirmed that its own systems were not breached and that devices, private keys, and wallet backups remain untouched. [^4]\n\nTrezor stated it repeatedly received written confirmation from ShipMonk that the data had been deleted, but learned that the records were not actually removed. [^5]\n\nTrezor first announced in August 2026 that data from 11,742 customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal had been exposed, with names, emails, phone numbers and shipping addresses leaked. [^6]\n\nTrezor said its third-party fulfillment partner, ShipMonk, had falsely reassured the company about deleting customer data, and that Trezor repeatedly requested and received written assurance of deletion in line with its contract and data policy. [^7]\n\nTrezor said the leaked data from the expanded breach came from orders made between November 2019 and August 2021. [^8]",
    "cited": "[{\"statement\":\"Trezor announced on September 4, 2026, that an additional 67,000 U.S. customers had their data exposed in a breach at its shipping partner, ShipMonk.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-04T11:32:49.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"Trezor, a Prague-based hardware wallet manufacturer, said on 2026-09-04 that an additional 67,000 US customers had their names, emails, phone numbers, shipping addresses and order numbers leaked in a data breach.\",\"source\":\"bitcoinmagazine.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-04T20:30:14.000Z\",\"publisher_count\":1,\"sources\":[\"bitcoinmagazine.com\"]},{\"statement\":\"The exposed records cover orders placed between November 2019 and August 2021 and include names, phone numbers, and home addresses.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-04T11:32:49.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"Trezor confirmed that its own systems were not breached and that devices, private keys, and wallet backups remain untouched.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-04T11:32:49.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"Trezor stated it repeatedly received written confirmation from ShipMonk that the data had been deleted, but learned that the records were not actually removed.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-04T11:32:49.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"Trezor first announced in August 2026 that data from 11,742 customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal had been exposed, with names, emails, phone numbers and shipping addresses leaked.\",\"source\":\"bitcoinmagazine.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-04T20:30:14.000Z\",\"publisher_count\":1,\"sources\":[\"bitcoinmagazine.com\"]},{\"statement\":\"Trezor said its third-party fulfillment partner, ShipMonk, had falsely reassured the company about deleting customer data, and that Trezor repeatedly requested and received written assurance of deletion in line with its contract and data policy.\",\"source\":\"bitcoinmagazine.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-04T20:30:14.000Z\",\"publisher_count\":1,\"sources\":[\"bitcoinmagazine.com\"]},{\"statement\":\"Trezor said the leaked data from the expanded breach came from orders made between November 2019 and August 2021.\",\"source\":\"bitcoinmagazine.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-04T20:30:14.000Z\",\"publisher_count\":1,\"sources\":[\"bitcoinmagazine.com\"]}]",
    "kind": "news"
  },
  "receipt_verify": "Ed25519 over the dot-joined string `slice_hash.cursor_from.cursor_to.view.view_version.row_count`; public_key and sig are base64url of the raw 32-byte key / 64-byte signature",
  "receipt": null,
  "receipt_note": "this revision predates receipt-keeping (before v0.37.0); the filed row lives in the record",
  "generation_chain": {
    "wire": {
      "stream": "fountain_news",
      "story_id": "f0e8b103d6ddb3adbee6b009f65b5374",
      "thread_id": "131b51c02d320fc39c68287db35dcf81",
      "thread_label": "ShipMonk",
      "novelty": "UPDATE",
      "content_hash": "10f59f85405b2a46157adec2f4080a15a7474f372d48bdd40f1012140d98e523",
      "last_published_at": "2026-09-04T20:30:14.000Z",
      "read_receipt": {
        "slice_hash": "9c69d9730b8bd17104085e79f74e1a4efef5a04f5f6abba71ea09b0703f9c6bc",
        "cursor_from": "eyJ0cyI6IjIwMjYtMDktMDRUMTg6MDE6MDAuMDAwMDAwWiIsImlkIjoiNDM2Y2FhODVhZGY5YzZmODIwOGIxNDJiYzM5ZWRjYWMiLCJ2IjoiMSJ9",
        "cursor_to": "eyJ0cyI6IjIwMjYtMDktMDRUMjE6MzA6MDkuMDAwMDAwWiIsImlkIjoiYmVhZjQxZWQ0ODJiNmEwYThmZWFhZDJmNmMyYTdjZmEiLCJ2IjoiMSJ9",
        "view": "v_fountain_news",
        "view_version": "1",
        "row_count": 100,
        "window_days": 3,
        "bytes_scanned": 8103881,
        "credits": 8,
        "price_per_100_rows": 8,
        "sig": "QGKP8ErwhgOPvWKjMKa-3fV0B2sfg38R9xvdMRLgkKbByUGkFwlFOLugrl03UCd9BIMbjf9bTt-Cy7yZGdFaBg",
        "public_key": "bMUigy8O0jOnBxQ4Sc-5lwhIZ8LQVAhxMbR7qESVuUE",
        "signer_path": "lakehouse/data-extract/v1",
        "alg": "Ed25519",
        "signed": true
      }
    },
    "written_at": "2026-09-05T00:35:38.801Z"
  },
  "cited_facts": [
    {
      "statement": "Trezor announced on September 4, 2026, that an additional 67,000 U.S. customers had their data exposed in a breach at its shipping partner, ShipMonk.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-04T11:32:49.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "Trezor, a Prague-based hardware wallet manufacturer, said on 2026-09-04 that an additional 67,000 US customers had their names, emails, phone numbers, shipping addresses and order numbers leaked in a data breach.",
      "source": "bitcoinmagazine.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-04T20:30:14.000Z",
      "publisher_count": 1,
      "sources": [
        "bitcoinmagazine.com"
      ]
    },
    {
      "statement": "The exposed records cover orders placed between November 2019 and August 2021 and include names, phone numbers, and home addresses.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-04T11:32:49.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "Trezor confirmed that its own systems were not breached and that devices, private keys, and wallet backups remain untouched.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-04T11:32:49.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "Trezor stated it repeatedly received written confirmation from ShipMonk that the data had been deleted, but learned that the records were not actually removed.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-04T11:32:49.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "Trezor first announced in August 2026 that data from 11,742 customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal had been exposed, with names, emails, phone numbers and shipping addresses leaked.",
      "source": "bitcoinmagazine.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-04T20:30:14.000Z",
      "publisher_count": 1,
      "sources": [
        "bitcoinmagazine.com"
      ]
    },
    {
      "statement": "Trezor said its third-party fulfillment partner, ShipMonk, had falsely reassured the company about deleting customer data, and that Trezor repeatedly requested and received written assurance of deletion in line with its contract and data policy.",
      "source": "bitcoinmagazine.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-04T20:30:14.000Z",
      "publisher_count": 1,
      "sources": [
        "bitcoinmagazine.com"
      ]
    },
    {
      "statement": "Trezor said the leaked data from the expanded breach came from orders made between November 2019 and August 2021.",
      "source": "bitcoinmagazine.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-04T20:30:14.000Z",
      "publisher_count": 1,
      "sources": [
        "bitcoinmagazine.com"
      ]
    }
  ],
  "note": "A signature proves who filed this and that it has not changed since. It never makes a claim true."
}