Full story
ShipMonk breach exposes 13,689
Hardware wallet maker Trezor disclosed that a breach at its fulfillment partner ShipMonk exposed order data for 13,689 customers, with the company saying the incident affected customers who received orders 90 days prior to August 8.
“13,689 customers”
Trezor said 11,742 customers had their names, emails, phone numbers, and shipping addresses leaked, while another 1,947 customers had just their names, cities and emails exposed.

In a Thursday post, Trezor said, "On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data," and it added that its operations or services were not impacted.
BleepingComputer reported that the breach affected customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026.
Trezor also warned that affected customers "could experience an increase in phishing attempts" even though it said its systems and devices remain secure.
Phishing risk and prior leaks
Trezor told customers to treat unexpected contact with suspicion and warned that scammers can use leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor.
In its disclosure, Trezor emphasized, "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts," and it said it is continuing to investigate the incident.

BleepingComputer reported that ShipMonk told customers the attackers exploited a vulnerability in the third-party analytics platform Metabase, and that Metabase had patched the vulnerability and invalidated all active sessions.
The breach comes after other Trezor-related incidents, including a January 2024 disclosure that 66,000 users who interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed.
Bitcoin Magazine also pointed to a broader pattern, noting that in 2020 an unauthorized party accessed Ledger’s e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers.
What Trezor says comes next
Trezor said the scope was limited by a policy requiring partners to delete or anonymize order data 90 days after delivery, which it said meant older orders were no longer held in ShipMonk’s systems.
“delete or anonymize order data 90 days after delivery”
Decrypt reported that Trezor attributed the limited scope to a policy requiring partners to delete or anonymize order data 90 days after delivery, and it said customers who did not receive a notification email are not affected.
Trezor also announced an Anonymous Delivery option, with ForkLog saying it would allow customers to pick up devices from lockers, receive packages in plain packaging, and ensure delivery data is not retained.
ForkLog added that the service is expected to launch in the EU by September and in the US by the end of the year, while Trezor continued to investigate the breach.
CoinDesk reported that Trezor told it it has no confirmed cases of the exposed data being published, shared, or offered for sale yet, and that it is unaware of any scam or hack attempt linked to the incident so far.
