A recent security incident involving ShipMonk has put thousands of Trezor hardware wallet customers at increased risk of phishing attacks. This breach, however, did not compromise Trezor’s own systems or devices.
Details of the Breach
On August 10, 2026, Trezor announced that ShipMonk, a logistics partner, reported unauthorized access to systems containing customer order data. This breach did not affect Trezor’s internal infrastructure, wallets, or firmware but exposed personal information that could be exploited in social engineering scams.
The breach impacted approximately 13,689 customers who placed orders between May 10 and August 8, 2026. Among these, 11,742 customers had full exposure of their name, email address, phone number, and shipping address, while 1,947 experienced partial exposure limited to name, city, and email.
Global Impact and Trezor’s Response
The compromised shipments were destined for the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor highlighted that the breach was limited due to its strict 90-day data retention policy, which ensures the deletion or anonymization of order-related personal data after 90 days.
ShipMonk, responsible for storing and shipping Trezor products in various countries, required this data to complete deliveries. Trezor assured that only information necessary for parcel fulfillment was involved, including name, email, order number, phone, and shipping address.
Customers have been notified by email from [email protected]. Those who did not receive this communication are not part of the affected group but should verify their status through their inbox.
Security Advisories and Future Developments
Although Trezor’s devices and systems remain secure, leaked contact details pose a risk of phishing attacks. Users should be cautious of any unexpected requests for personal information or wallet recovery details, cross-referencing any such messages with official Trezor communication channels.
To minimize future risks, Trezor plans to introduce an ‘Anonymous Delivery’ option, featuring neutral packaging and automatic deletion of shipping identifiers post-delivery. This service is expected to launch in the EU by September 2026 and in the US by the end of the year.
Trezor, founded in 2013, has taken this breach seriously, apologizing to affected customers and emphasizing the importance of staying vigilant. The company is collaborating with ShipMonk to secure and enhance the affected systems and continues to directly notify customers to ensure awareness and protection.
