Trezor says a breach at shipping provider ShipMonk exposed customer order data for people who bought Trezor hardware wallets, affecting nearly 14,000 customers. Trezor said ShipMonk notified it on August 10, 2026 of unauthorized access to systems holding order records. Exposed data included full names, shipping addresses, email addresses, and phone numbers for 11,742 customers, with partial exposure for 1,947 more. Trezor says its own systems and devices were not compromised.
Why it matters: Affected customers face a credible risk of targeted phishing, scam calls, and seed-phrase theft attempts because attackers now have detailed order information tied to cryptocurrency hardware wallets. Users should treat any message claiming to be from Trezor, a bank, or an exchange with extra caution and never share wallet recovery seeds.
2026.08.14
98% relevant
This article is a direct update on the same ShipMonk-related Trezor customer-data breach, adding refined counts, affected countries, the May 10 to August 8 order window for 11,742 customers, an additional 1,947 exposed records with partial details, and Trezor's plan for an anonymous delivery option.
Ionut Arghire
2026.08.14
99% relevant
This article is directly about the same ShipMonk breach affecting Trezor customers, adding counts by data type exposed, affected countries and order window, and that ShipMonk reportedly linked the intrusion to an exploited Metabase vulnerability likely tied to the recent SQL injection zero-day and ShinyHunters claims.
Sergiu Gatlan
2026.08.13
100% relevant
This article establishes a new breach story centered on Trezor customer data exposure via ShipMonk, not an update to an existing tracked event.
← Back to all stories