Published

Trezor Says ShipMonk Breach Exposed Order Data for 13,689 Customers
Image: Yellow

Technology and Science · 13 August, 2026 · 3 min read

Trezor Says ShipMonk Breach Exposed Order Data for 13,689 Customers

Happened

Data breach at ShipMonk exposed personal data for 13,689 Trezor customers. Exposed data included full names, shipping addresses, email addresses, and phone numbers.

Split on

Whether the article mentions the breach’s underlying cause (Metabase zero-day SQLi).

Left out

10 of 12 outlets skipped it: shipMonk said the attackers exploited a Metabase SQL-injection zero-day.

21outlets compared

@coindeskAMBCryptoBenzingaBitboBitcoin MagazineBleepingComputerBlockchain NewsCoinDesk

Same story, two versions

tap a side to read it in full

BleepingComputerBleepingComputer

“attackers exploited a vulnerability in the third-party analytics platform Metabase”
Read the original ↗

Bitcoin MagazineBitcoin Magazine

“its third-party fulfillment partner, ShipMonk, had experienced ‘unauthorized access’”
Read the original ↗
VS

Some outlets add root-cause detail; others stop at partner compromise.

ShipMonk breach exposes 13,689

Hardware wallet maker Trezor disclosed that a breach at its fulfillment partner ShipMonk exposed order data for 13,689 customers, with the company saying the incident affected customers who received orders 90 days prior to August 8. Trezor said 11,742 customers had their names, emails, phone numbers, and shipping addresses leaked, while another 1,947 customers had just their names, cities and emails exposed. In a Thursday post, Trezor said, "On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data," and it added that its operations or services were not impacted.

BleepingComputer reported that the breach affected customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026. BTrezor also warned that affected customers "could experience an increase in phishing attempts" even though it said its systems and devices remain secure.

Image from @coindesk
@coindesk@coindesk

Phishing risk and prior leaks

Trezor told customers to treat unexpected contact with suspicion and warned that scammers can use leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor. In its disclosure, Trezor emphasized, "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts," and it said it is continuing to investigate the incident. BleepingComputer reported that ShipMonk told customers the attackers exploited a vulnerability in the third-party analytics platform Metabase, and that Metabase had patched the vulnerability and invalidated all active sessions.B

The breach comes after other Trezor-related incidents, including a January 2024 disclosure that 66,000 users who interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed. Bitcoin Magazine also pointed to a broader pattern, noting that in 2020 an unauthorized party accessed Ledger’s e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers.

Image from AMBCrypto
AMBCryptoAMBCrypto

What Trezor says comes next

Trezor said the scope was limited by a policy requiring partners to delete or anonymize order data 90 days after delivery, which it said meant older orders were no longer held in ShipMonk’s systems. Decrypt reported that Trezor attributed the limited scope to a policy requiring partners to delete or anonymize order data 90 days after delivery, and it said customers who did not receive a notification email are not affected. Trezor also announced an Anonymous Delivery option, with ForkLog saying it would allow customers to pick up devices from lockers, receive packages in plain packaging, and ensure delivery data is not retained.

ForkLog added that the service is expected to launch in the EU by September and in the US by the end of the year, while Trezor continued to investigate the breach. CoinDesk reported that Trezor told it it has no confirmed cases of the exposed data being published, shared, or offered for sale yet, and that it is unaware of any scam or hack attempt linked to the incident so far.