NewsCryptoTrezor Warns of Phishing Risk After ShipMonk Breach Exposes 13,689 Customer Records

Trezor Warns of Phishing Risk After ShipMonk Breach Exposes 13,689 Customer Records

Author: DailyCoin·

Key Takeaways

  • A data breach at Trezor's third-party logistics provider ShipMonk exposed the personal information of 13,689 customers, including names, email addresses, phone numbers, and shipping addresses.
  • Trezor has confirmed that there is no evidence its internal systems, hardware wallets, wallet backups, or cryptocurrency holdings were compromised in the incident.
  • The affected records primarily involved orders placed between May 10 and August 8, 2026, and shipped to the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
  • Trezor plans to launch an Anonymous Delivery option with dedicated checkout, locker pickup, and neutral packaging in the EU by September 2026 and in the US by the end of 2026.
  • This is the first breach since Trezor's founding in 2013 to expose customer phone numbers and shipping addresses, and it follows earlier third-party incidents in 2022 and 2024.
Trezor Warns of Phishing Risk After ShipMonk Breach Exposes 13,689 Customer Records

Hardware cryptocurrency wallet manufacturer Trezor warned on Thursday of an elevated phishing risk following a data breach at its third-party logistics provider, ShipMonk, which exposed the personal information of 13,689 customers. The compromised data includes names, addresses, phone numbers, and email addresses.

The company stated that there is no evidence wallet backups, cryptocurrency holdings, or Trezor's internal systems were compromised. However, Trezor cautioned that the leaked customer data could be leveraged to craft more convincing phishing scams targeting affected individuals.

Details of the Breach

ShipMonk notified Trezor on August 10, 2026, that an unauthorized actor had accessed systems containing customer data. ShipMonk, a US-based e-commerce fulfillment provider, handles logistics services for Trezor including product storage and shipping across multiple markets.

Of the 13,689 affected customers, 11,742 had their full names, email addresses, phone numbers, and shipping addresses exposed. The remaining 1,947 customers had partial information compromised, including names, city names, and email addresses. Trezor is continuing to work with ShipMonk to determine the exact exposure window for those 1,947 customers.

The affected records primarily involved new-customer orders placed between May 10 and August 8, 2026, and shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.

Trezor shared the news publicly via its official X account:

We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…

— Trezor (@Trezor) August 13, 2026

https://x.com/Trezor/status/2087885428313543059

Data Retention and Customer Notification

Trezor stated that its 90-day data-retention policy with logistics partners helped limit the scope of the incident, as older order information had already been deleted or anonymized.

Affected customers were individually notified by email from help@trezor.io. Customers who did not receive a notification are not affected, according to the company.

No Compromise of Trezor Systems or Wallets

Trezor confirmed there is no indication that its internal systems, hardware wallets, or wallet backups were compromised. The company reiterated that customers should never enter their wallet backup online or share it with anyone.

The primary risk arising from the breach stems from the exposed personal information, which could be used to impersonate Trezor or create more convincing fraudulent communications.

Phishing Risk from Exposed Data

Names, phone numbers, email addresses, and shipping details can provide attackers with contextual information for targeted phishing campaigns. A message referencing a customer's name, recent Trezor purchase, or delivery details may appear more credible than a generic scam.

Attackers could subsequently attempt to persuade victims to disclose sensitive information, click malicious links, or reveal their wallet backup. Trezor users are advised to be particularly cautious about unsolicited messages claiming to involve wallet security, account problems, refunds, deliveries, or other urgent matters.

Trezor's Response and Planned Measures

Trezor described the incident as the first breach since its founding in 2013 to expose customer phone numbers and shipping addresses, and the company apologized to affected users.

The company plans to introduce an Anonymous Delivery option featuring dedicated checkout, locker pickup, neutral packaging, and automatic deletion of shipping identifiers. Trezor aims to launch the service in the EU by September 2026 and in the US by the end of 2026.

History of Third-Party Incidents

The ShipMonk breach follows earlier security incidents involving Trezor's third-party providers. In January 2024, unauthorized access to Trezor's third-party support portal potentially exposed the names and email addresses of approximately 66,000 users. A separate Mailchimp breach in 2022 also affected Trezor customers and was followed by phishing campaigns targeting cryptocurrency users.

Other hardware wallet manufacturers have experienced similar incidents. Ledger suffered a major data breach in 2020 that exposed more than 1 million email addresses and hundreds of thousands of customer records, some of which were subsequently used in cryptocurrency scams.

Broader Security Implications

These incidents highlight a broader security challenge for hardware wallet users: attackers do not necessarily need access to a wallet or its cryptographic keys to target its owner. Personal information obtained through a third-party breach can be sufficient to make a scam appear legitimate. The recurring pattern of vendor-side exposures across the hardware wallet industry also underscores that self-custody solutions, while protecting private keys, still depend on physical supply chains and service providers that create data surfaces beyond the wallet itself. Affected customers in EU member states and other jurisdictions with data protection regulations may have additional rights regarding their exposed personal data.