Trezor says ShipMonk breach exposed order data of 13,689 customers

Trezor says ShipMonk breach exposed order data of 13,689 customers

N
News Editor
2026-08-13 14:40:06
Trezor said on Aug. 13 that a data breach at fulfillment partner ShipMonk exposed order-related personal information tied to 13,689 customers, while wallet devices, private keys, seed phrases, and Trezor’s own systems were not affected. According to the company, 11,742 customers had full records exposed, including names, phone numbers, email addresses, and shipping addresses. Another 1,947 customers saw partial exposure involving names, cities, and email addresses. The affected orders were created between May 10 and Aug. 8 and spanned the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor warned that the main follow-on risk is phishing, urging users to be cautious with unexpected calls, texts, or emails and never enter a wallet backup seed phrase online. The incident marks the first leak of customer phone numbers and addresses in Trezor’s 13-year operating history.

Trezor said a data breach at fulfillment partner ShipMonk exposed order information linked to 13,689 customers, while hardware wallet devices, private keys, backup seed phrases, and Trezor’s own systems were not affected.

Order details were exposed, not wallet credentials

According to Decrypt, Trezor confirmed the incident on Aug. 13 and said the breach occurred at ShipMonk, one of its shipping partners. The company said sensitive order data was exposed after the vendor incident, but Trezor’s internal systems were not breached.

Trezor said 11,742 customers had full records exposed, including names, phone numbers, email addresses, and shipping addresses. Another 1,947 customers were affected by a partial exposure involving names, cities, and email addresses.

Affected orders were created between May 10 and Aug. 8

The company said the impacted orders were created from May 10 through Aug. 8. The affected customers were located across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.

Trezor also posted on X that a data breach at a shipping vendor had exposed sensitive order information.

Trezor warns users about phishing attempts

Trezor said customer funds remain safe, but warned that the main risk after the leak is phishing. The company urged users to treat unexpected phone calls, text messages, and emails with caution, and said they should never enter a wallet backup seed phrase online.

The report said this is the first time in Trezor’s 13 years of operation that customer phone numbers and addresses have been exposed. It also pointed to the 2020 Ledger leak of 272,000 customer records, after which some users faced extortion and even physical threats.

As described in the report, the most immediate danger from leaked personal information may not be direct theft of wallet funds, but fraudulent messages built around a customer’s real name and address to trick them into handing over a seed phrase.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
90

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.