The useful thing to notice about this month''s breaches is that in several cases the company you trusted didn''t do anything wrong. Its shipping provider did. Or its software vendor. Or a distributor three steps removed from you, whose name you''ve never once seen.
What happened
Trezor, which makes cryptocurrency hardware wallets, said 11,742 customers had names, shipping addresses, email addresses and phone numbers exposed — through its shipping provider, not its own systems. Another 1,947 people had some data compromised. The affected span the US, UK, Sweden, Colombia, Brazil, Italy and Portugal.
Sit with what that list is for a second: home addresses of people known to own crypto hardware. That isn''t an abstract privacy loss. It''s a targeting list.
In the same stretch, Unlimited Technology Systems reported 3.8 million people exposed with an unusually complete record — full names, Social Security numbers, dates of birth, email and mailing addresses, phone numbers, demographic details, government IDs, insurance cards, medical information. Wesco, a supply chain and distribution firm, faced claims of 2.6 million records covering customer and employee data, CRM profiles, credit identifiers and access information. SafePal reported 39,798 customers affected, with the data allegedly up for sale.
For scale: 471.2 million victim notices went out across 1,803 compromises in the first half of 2026 alone.
Why the pattern beats the numbers
You get to choose which companies you deal with. You don''t get to choose their shipping partners, payment processors, CRM vendors, or the analytics firm somebody signed with last spring.
Every company you use sits on top of a supply chain of data handlers, and your information travels through all of it. Your care in picking a reputable brand stops at that brand''s procurement decisions. Which is why "I only use trustworthy services" has quietly stopped working as a strategy.
It also explains why the stolen fields keep getting richer. Breach a shipping provider, get addresses. Breach a healthcare software vendor and you get Social Security numbers, government IDs and medical records in a single file — because that vendor needed all of it to do the job it was hired for.
What to actually do
Freeze your credit. Not a fraud alert — an actual freeze, at all three bureaus. It''s free, takes about twenty minutes, and it''s the one control that genuinely devalues a stolen Social Security number. Lift it temporarily when you need credit.
Assume your address is out there if you own anything worth physically stealing. Trezor is the clearest case: people who bought hardware precisely to keep assets offline now sit on a list linking their names to their front doors. If that''s you, be suspicious of unexpected packages, "replacement device" offers, and anything that arrives with a QR code on it.
Expect targeted phishing, not generic spam. Someone holding your name, address, phone number and the exact company you bought from can write a message that sails past every instinct you use to spot a fake. The defence has to be procedural rather than perceptual: never act on an inbound message. Go to the company through a channel you already had.
And check that a breach notification is real before you respond to it. Those emails are a favourite phishing template at the moment.
The uncomfortable part
There''s no consumer-side fix for a third-party breach. What you can do is make a stolen record worth less: freeze credit, unique passwords in a manager, hardware-backed two-factor wherever it''s offered, and a working assumption that any detail a company holds about you will eventually circulate. Plan for the leak instead of trying to prevent it.
Image: panumas nikhomkhai, via Pexels





