ShipMonk Breach Exposes Trezor Customer Data @Trezor has confirmed a high-severity data breach originating from one of its third-party logistics partners. The breach was caused by a security
ShipMonk Breach Exposes Trezor Customer Data
@Trezor has confirmed a high-severity data breach originating from one of its third-party logistics partners. The breach was caused by a security failure at ShipMonk, which stores and ships Trezor products, after an unauthorized party accessed systems holding customer data. A total of 13,689 customers across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal are affected.
Some 11,742 customers had their full details taken, while another 1,947 had names, cities, and email addresses exposed.Those affected placed orders between May 10 and August 8, 2026. The exposed information includes full names, shipping addresses, phone numbers, email addresses, and order numbers.
Trezor's 90-day data retention policy appears to have limited the scope of the incident, preventing exposure of records older than that window.
Devices Secure, but Phishing Risk Remains
Trezor stated that its systems were not compromised and the devices remain secure, but it warns affected customers to be vigilant against carefully designed phishing attacks that exploit the leaked information.
The concern is well-founded. Physical home addresses and phone numbers in the hands of bad actors create a clear pathway to targeted social engineering, where attackers impersonate Trezor support or pose as couriers to extract wallet credentials from victims.
Trezor said it is bringing forward an Anonymous Delivery option using locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers, targeting the European Union by September and the United States by the end of the year.
This is not the first time Trezor has been caught up in a third-party security failure. In January 2024, the company's support site suffered a data breach caused by unauthorized access to a third-party support ticketing portal, exposing the sensitive information of roughly 66,000 users. The latest incident underlines the growing risk that supply chain and logistics partners pose to hardware wallet manufacturers, whose customers are by definition high-value targets.
Affected users should treat any unsolicited communication referencing their Trezor order as suspicious and avoid clicking links or sharing any account or seed-phrase information.
Sources:Decrypt: Trezor Customer Data Exposed in Shipping Partner BreachBleeping Computer: Trezor's Support Platform Abused in Crypto Theft Phishing Attacks