Trezor and ShipMonk: Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers

Trezor and ShipMonk: Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers

Trezor Customers Face Phishing Risks After Third-Party Logistics Breach

On August 10, 2026, hardware wallet manufacturer Trezor disclosed a data breach involving ShipMonk, one of its shipping providers, exposing personal details of thousands of customers. While Trezor’s own systems and devices remained uncompromised, the incident heightened phishing risks for affected users.

The breach impacted 13,689 customers who placed orders between May 10 and August 8, 2026, across the U.S., U.K., Sweden, Colombia, Brazil, Italy, and Portugal. Of these, 11,742 customers had full exposure of names, email addresses, phone numbers, and shipping addresses, while 1,947 had partial exposure limited to names, cities, and emails. Trezor’s 90-day data retention policy limited the scope, as older records were no longer stored by ShipMonk.

ShipMonk, which handles storage and shipping for Trezor, held the exposed data including names, emails, order numbers, phone numbers, and shipping addresses only as required for delivery. Trezor confirmed that no wallet security or firmware was affected, but the leaked details could be weaponized for phishing, spoofed calls, or fraudulent messages impersonating Trezor or financial services.

This marks the first time since Trezor’s 2013 founding that customer phone numbers and shipping addresses have been exposed in a breach. The company has notified affected users via help@trezor.io and urged caution against unsolicited requests for personal or wallet recovery information.

Trezor is working with ShipMonk to investigate and secure the affected systems. To mitigate future risks, the company plans to introduce an "Anonymous Delivery" option by September 2026 (EU) and end of 2026 (U.S.), featuring neutral packaging, locker pickup, and automatic deletion of shipping identifiers. Operations remain unaffected, and Trezor continues direct customer outreach.

Source: https://cybersecuritynews.com/trezor-shipmonk-data-breach/

Trezor TPRM report: https://www.rankiteo.com/company/trezor

ShipMonk TPRM report: https://www.rankiteo.com/company/shipmonk

"id": "treshi1786631044",
"linkid": "trezor, shipmonk",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '13,689',
                        'industry': 'Cryptocurrency',
                        'location': 'Global (HQ: Czech Republic)',
                        'name': 'Trezor',
                        'type': 'Hardware Wallet Manufacturer'},
                       {'industry': 'Logistics/Shipping',
                        'name': 'ShipMonk',
                        'type': 'Third-Party Logistics Provider'}],
 'attack_vector': 'Third-Party Vendor Compromise',
 'customer_advisories': 'Urged caution against unsolicited requests for '
                        'personal or wallet recovery information.',
 'data_breach': {'number_of_records_exposed': '13,689',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information)',
                 'type_of_data_compromised': ['Names',
                                              'Email addresses',
                                              'Phone numbers',
                                              'Shipping addresses',
                                              'Order numbers']},
 'date_detected': '2026-08-10',
 'date_publicly_disclosed': '2026-08-10',
 'description': 'On August 10, 2026, hardware wallet manufacturer Trezor '
                'disclosed a data breach involving ShipMonk, one of its '
                'shipping providers, exposing personal details of thousands of '
                'customers. While Trezor’s own systems and devices remained '
                'uncompromised, the incident heightened phishing risks for '
                'affected users.',
 'impact': {'brand_reputation_impact': 'Heightened phishing risks for affected '
                                       'users',
            'data_compromised': 'Personal details (names, email addresses, '
                                'phone numbers, shipping addresses, order '
                                'numbers)',
            'identity_theft_risk': 'Increased risk of phishing, spoofed calls, '
                                   'or fraudulent messages',
            'systems_affected': "ShipMonk's logistics systems"},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Third-party vendors can introduce significant risks; need '
                    'for stricter data retention policies and enhanced '
                    'customer data protection measures.',
 'post_incident_analysis': {'corrective_actions': "Introduction of 'Anonymous "
                                                  "Delivery' option, stricter "
                                                  'data retention policies, '
                                                  'and enhanced third-party '
                                                  'vendor monitoring',
                            'root_causes': 'Third-party logistics provider '
                                           '(ShipMonk) breach exposing '
                                           'customer data'},
 'recommendations': "Implement 'Anonymous Delivery' options, reduce data "
                    'retention periods, and enhance monitoring of third-party '
                    'vendors.',
 'references': [{'source': 'Trezor Disclosure'}],
 'response': {'communication_strategy': 'Direct customer outreach via '
                                        'help@trezor.io',
              'containment_measures': 'Investigating and securing affected '
                                      'systems',
              'remediation_measures': "Introduction of 'Anonymous Delivery' "
                                      'option with neutral packaging, locker '
                                      'pickup, and automatic deletion of '
                                      'shipping identifiers'},
 'title': 'Trezor Customers Face Phishing Risks After Third-Party Logistics '
          'Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.