Trezor Says ShipMonk Breach Exposed Order Data for 13,689 Customers
Image: Yellow

Trezor Says ShipMonk Breach Exposed Order Data for 13,689 Customers

13 August, 2026.Technology and Science.21 sources

Data breach at ShipMonk exposed personal data for 13,689 Trezor customers. Exposed data included full names, shipping addresses, email addresses, and phone numbers.

21 outlets3 divides1 fact unevenly covered

Read them yourself

Do not take our word for it. Here is what they published.

All 21 outlets

Full story

ShipMonk breach exposes 13,689

Hardware wallet maker Trezor disclosed that a breach at its fulfillment partner ShipMonk exposed order data for 13,689 customers, with the company saying the incident affected customers who received orders 90 days prior to August 8.

13,689 customers

BleepingComputerBleepingComputer

Trezor said 11,742 customers had their names, emails, phone numbers, and shipping addresses leaked, while another 1,947 customers had just their names, cities and emails exposed.

Image from @coindesk
@coindesk@coindesk

In a Thursday post, Trezor said, "On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data," and it added that its operations or services were not impacted.

BleepingComputer reported that the breach affected customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026.

Trezor also warned that affected customers "could experience an increase in phishing attempts" even though it said its systems and devices remain secure.

Phishing risk and prior leaks

Trezor told customers to treat unexpected contact with suspicion and warned that scammers can use leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor.

In its disclosure, Trezor emphasized, "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts," and it said it is continuing to investigate the incident.

Image from AMBCrypto
AMBCryptoAMBCrypto

BleepingComputer reported that ShipMonk told customers the attackers exploited a vulnerability in the third-party analytics platform Metabase, and that Metabase had patched the vulnerability and invalidated all active sessions.

The breach comes after other Trezor-related incidents, including a January 2024 disclosure that 66,000 users who interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed.

Bitcoin Magazine also pointed to a broader pattern, noting that in 2020 an unauthorized party accessed Ledger’s e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers.

What Trezor says comes next

Trezor said the scope was limited by a policy requiring partners to delete or anonymize order data 90 days after delivery, which it said meant older orders were no longer held in ShipMonk’s systems.

delete or anonymize order data 90 days after delivery

DecryptDecrypt

Decrypt reported that Trezor attributed the limited scope to a policy requiring partners to delete or anonymize order data 90 days after delivery, and it said customers who did not receive a notification email are not affected.

Trezor also announced an Anonymous Delivery option, with ForkLog saying it would allow customers to pick up devices from lockers, receive packages in plain packaging, and ensure delivery data is not retained.

ForkLog added that the service is expected to launch in the EU by September and in the US by the end of the year, while Trezor continued to investigate the breach.

CoinDesk reported that Trezor told it it has no confirmed cases of the exposed data being published, shared, or offered for sale yet, and that it is unaware of any scam or hack attempt linked to the incident so far.