NewsCryptoTrezor Discloses ShipMonk Data Breach Affecting 13,700 Customers Across Seven Countries

Trezor Discloses ShipMonk Data Breach Affecting 13,700 Customers Across Seven Countries

Author: Metaverse Post·

Key Takeaways

  • •A data breach at Trezor's logistics provider ShipMonk exposed personal information of approximately 13,700 customers across seven countries, including the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
  • •Of those affected, 11,742 customers experienced full exposure of names, shipping addresses, phone numbers, and email addresses, while 1,947 customers had partial exposure limited to name, city, and email.
  • •Trezor confirmed that its own internal systems and hardware devices were not compromised, and the breach scope was constrained by a 90-day data retention policy requiring fulfillment partners to delete or anonymize order records after delivery.
  • •In response to the incident, Trezor is accelerating an Anonymous Delivery service that allows customers to use nicknames, collect parcels from automated lockers, and receive unbranded packaging, targeted for EU launch by September 2026 and US availability by year-end.
  • •Trezor warned that leaked customer details could enable sophisticated phishing campaigns, as attackers aware of a hardware wallet purchase can craft more plausible social-engineering attempts impersonating banks, exchanges, or Trezor itself.
Trezor Discloses ShipMonk Data Breach Affecting 13,700 Customers Across Seven Countries

Hardware wallet manufacturer Trezor has disclosed a data breach at its third-party logistics provider, ShipMonk, that exposed the personal information of approximately 13,700 customers across seven countries.

Trezor, operated by Prague-based SatoshiLabs, is one of the most widely recognized hardware wallet brands in the cryptocurrency industry, alongside competitors such as Ledger. The incident underscores a recurring challenge for the sector: even when the cryptographic devices themselves remain secure, customer data held by vendors and fulfillment partners can become a high-value target. In 2020, Ledger suffered a major e-commerce database breach that exposed the personal details of roughly 270,000 customers, leading to widespread phishing campaigns and reports of physical extortion letters sent to affected users.

The company described the current incident as its first exposure of customer phone numbers and shipping addresses since its founding in 2013. Affected individuals are new customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders within the 90 days prior to August 8, 2026.

According to Trezor, unauthorized actors gained access to ShipMonk's systems around August 10, 2026, compromising order records containing full names, shipping addresses, phone numbers, and email addresses. Of those affected, 11,742 customers experienced full exposure of all four data categories, while an additional 1,947 customers faced partial exposure limited to name, city, and email.

Trezor emphasized that its own internal systems and hardware devices were not compromised. The breach scope was constrained by a 90-day data retention policy that requires fulfillment partners to delete or anonymize order records after delivery.

"We have some difficult news to share," Trezor stated in its original announcement. "Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data."

https://x.com/Trezor/status/2087885428313543059

All affected users have been contacted directly via email. Trezor warned that leaked personal details could enable more sophisticated phishing campaigns, with attackers potentially impersonating banks, cryptocurrency exchanges, or Trezor itself to extract sensitive information from customers. Knowing that an individual has purchased a hardware wallet allows attackers to tailor social-engineering attempts with a heightened degree of plausibility, a tactic observed following similar incidents at other wallet providers.

Anonymous Delivery and Enhanced Privacy Measures

In response to the incident, Trezor is accelerating the rollout of an "Anonymous Delivery" service intended to sever the link between hardware wallet purchases and customers' real-world identities. The feature, targeted for launch in the European Union by September 2026 and in the United States by year-end, will introduce a dedicated checkout flow allowing users to register under a nickname or label ID, collect parcels from automated lockers, and receive orders in unbranded packaging with generic sender labels. Carriers will communicate pickup codes exclusively via email or SMS, and shipping identifiers will be automatically deleted after delivery.

Trezor advised all customers to remain vigilant against phishing attempts via email, phone, or physical mail, and to never enter wallet recovery phrases on websites or share them with third parties.

The company confirmed that ShipMonk has secured the affected systems and strengthened its security posture following the incident. Trezor continues to investigate the full circumstances surrounding the breach.