Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A third-party logistics breach has put thousands of Trezor hardware wallet buyers at higher phishing risk, even though Trezor’s own systems and devices were not compromised.

On Monday, August 10, 2026, crypto hardware wallet maker Trezor said ShipMonk, one of its shipping providers, reported unauthorized access to systems holding customer order data.

The incident did not touch Trezor infrastructure, wallets, or firmware, but it did expose personal details that scammers can weaponize in social engineering campaigns.

According to Trezor, the breach affected roughly 13,689 customers who received orders between May 10 and August 8, 2026. Of those, 11,742 customers had full exposure of name, email address, phone number, and shipping address, while 1,947 had partial exposure limited to name, city, and email.

Trezor ShipMonk Data Breach

Impacted shipments were tied to destinations including the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor stressed that the scope stayed relatively contained because of its strict 90-day data retention policy, which also applies to fulfillment partners.

Under that policy, order-related personal data is deleted or anonymized 90 days after delivery, so older records were no longer held in ShipMonk systems and could not be accessed.

ShipMonk is the logistics partner that stores Trezor products and ships parcels in the US, UK, and several other countries. To complete delivery, carriers require a recipient name, shipping address, phone number, and email, which is why the provider held that information at all.

Trezor says only data needed for parcel fulfillment was involved: name, email, order number, phone number, and shipping address. The company has emailed affected customers from [email protected]. Anyone who did not receive that message is not part of the exposed set. If you are unsure, checking that inbox remains the clearest way to confirm status.

Trezor was clear that devices remain secure and that company systems were not breached. The practical risk is secondary: attackers can use leaked contact and address data to craft convincing phishing emails, spoofed phone calls, fraudulent letters, or impersonation of banks, crypto exchanges, or even Trezor support.

This is the first time since Trezor’s founding in 2013 that a breach has exposed customer phone numbers and shipping addresses, and the company called the situation serious while apologizing to those affected.

Customers should treat any urgent request for personal details or wallet recovery information as hostile. Cross-check unexpected messages against official Trezor blog posts and social channels, and never enter a wallet backup seed on a website or share it with anyone claiming to be support.

Paying with crypto, using disposable emails or virtual cards, and preferring a P.O. Box where practical can reduce future exposure when ordering physical hardware.

Trezor also said an “Anonymous Delivery” option is planned, with dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery, targeting the EU by September 2026 and the US by the end of 2026.

Operationally, Trezor reports no disruption to products or services. The company is working with ShipMonk on the investigation, says the partner has secured and hardened the affected systems, and continues direct customer notification so people can stay alert. For help, Trezor points users to its support chat.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.