Trezor says ShipMonk breach exposed order data for 13,689 customers

Trezor says ShipMonk breach exposed order data for 13,689 customers

N
News Editor
2026-08-13 14:04:09
Trezor said a breach at third-party shipping provider ShipMonk exposed personal and order data tied to 13,689 recent customers, raising both phishing and physical-security concerns. According to the company, 11,742 customers had their full name, email address, phone number and shipping address exposed, while another 1,947 had their name, city and email address exposed. The affected orders were delivered between May 10 and Aug. 8 to customers in the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal. ShipMonk notified Trezor on Aug. 10 that systems containing customer data had been accessed without authorization, and the investigation is still underway. Trezor said its own systems were not compromised and its devices remain secure. The company separately emailed all affected customers and said anyone who did not receive a message from help@trezor.io was not impacted. Trezor also pointed to its 90-day data-retention policy as a factor that limited the scope of the exposure and said it plans to introduce an Anonymous Delivery option in the European Union by September 2026 and in the U.S. by the end of 2026.

Trezor said a breach at third-party shipping provider ShipMonk exposed personal and order data belonging to 13,689 recent customers, including names and contact details that could be used in targeted phishing attacks. The exposure of shipping addresses also creates a potential physical-security risk because it links named customers to recent Trezor orders.

Two sets of customer records were exposed

In its disclosure, Trezor said 11,742 customers had their full name, email address, phone number and shipping address exposed. Another 1,947 customers had their name, city and email address exposed.

The affected orders were delivered between May 10 and Aug. 8 to customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor said ShipMonk informed it on Aug. 10 that systems containing customer data had been accessed without authorization. The investigation is ongoing.

Trezor says its own systems were not compromised

The company said its own systems were not affected and that Trezor devices remain secure. It also said all affected customers were contacted separately by email. According to the notice, customers who did not receive an email from help@trezor.io were not impacted.

Trezor warned recipients to expect more sophisticated phishing attempts. It said scammers could use the exposed information in fake emails, phone calls and letters, or impersonate Trezor, a bank or a crypto exchange. The company told customers never to enter a wallet backup on a website, never to share it with anyone, and to verify communications through Trezor’s official channels.

Shipping addresses add a physical-security concern

The exposed records identify people who recently received an order from Trezor and, for most of those affected, include the address where the package was delivered. That combination can make a fake support message more convincing. It could also help a criminal choose a physical target.

A public repository maintained by Jameson Lopp tracks known physical attacks against bitcoin and crypto owners dating back to 2014, including home invasions, kidnappings, robberies and extortion. Trezor described a potential risk in its disclosure and did not report any compromise of its own systems or devices.

A 90-day retention policy limited the scope

Trezor said the scale of the breach was limited by a 90-day data-retention policy that also applies to its fulfillment partners. Its published privacy policy says names, addresses, phone numbers and email addresses used for delivery are deleted from Trezor and fulfillment-partner systems after 90 days, except in cases involving unresolved order issues.

The company said this was the first breach since Trezor was founded in 2013 to expose customer phone numbers and shipping addresses. Trezor plans to make an Anonymous Delivery option available in the European Union by September 2026 and in the U.S. by the end of 2026. The proposed feature includes locker pickup and automatic deletion of shipping identifiers after delivery.

Order-data exposure has hit hardware-wallet customers before

Exposure of order data has repeatedly affected customers of hardware-wallet companies without necessarily compromising the wallets themselves. Ledger said a January 2026 incident at commerce provider Global-e exposed names, postal addresses, email addresses, phone numbers and order details, while leaving Ledger devices and systems unaffected.

Ledger also disclosed in 2020 that an unauthorized party accessed its ecommerce and marketing database, exposing email addresses and, for a subset of customers, names, postal addresses, phone numbers and order information.

ShipMonk has secured the affected systems

Trezor said ShipMonk has secured and hardened the affected systems while the companies work to determine exactly what happened and which data was accessed.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
60

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.