A recent data breach involving a third-party logistics provider has compromised the personal information of over 13,000 customers of Trezor, a leading manufacturer of cryptocurrency hardware wallets. While Trezor’s internal systems and devices remain secure, the incident has heightened the risk of phishing attacks targeting affected individuals.
On August 10, 2026, Trezor disclosed that ShipMonk, one of its shipping partners, experienced unauthorized access to systems containing customer order data. This breach did not impact Trezor’s infrastructure, wallets, or firmware but did expose sensitive personal details that could be exploited in social engineering schemes.
The breach affected approximately 13,689 customers who received orders between May 10 and August 8, 2026. Of these, 11,742 customers had their full name, email address, phone number, and shipping address exposed, while 1,947 had partial exposure limited to their name, city, and email address.
Impacted shipments were destined for countries including the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor emphasized that the scope of the breach was limited due to its strict 90-day data retention policy, which also applies to its fulfillment partners. Under this policy, order-related personal data is deleted or anonymized 90 days after delivery, ensuring that older records were not accessible during the breach.
ShipMonk, responsible for storing and shipping Trezor products in several countries, held the compromised information necessary for parcel delivery, such as recipient names, shipping addresses, phone numbers, and email addresses.
Trezor has proactively contacted affected customers via email from [email protected]. Customers who did not receive this notification are not part of the exposed group. To confirm their status, individuals should check their inbox for this specific communication.
While Trezor’s devices and systems remain secure, the primary concern is that attackers may use the leaked contact and address data to craft convincing phishing emails, spoofed phone calls, fraudulent letters, or impersonate banks, cryptocurrency exchanges, or even Trezor support.
This incident marks the first time since Trezor’s founding in 2013 that customer phone numbers and shipping addresses have been exposed. The company has expressed its seriousness regarding the situation and apologized to those affected.
Customers are advised to treat any urgent requests for personal details or wallet recovery information as suspicious. It is crucial to cross-check unexpected messages against official Trezor blog posts and social channels and never to enter a wallet backup seed on a website or share it with anyone claiming to be support.
To mitigate future exposure when ordering physical hardware, customers can consider paying with cryptocurrency, using disposable emails or virtual cards, and opting for a P.O. Box where practical.
Looking ahead, Trezor plans to introduce an “Anonymous Delivery” option featuring dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery. This service is expected to launch in the EU by September 2026 and in the US by the end of 2026.
Operationally, Trezor reports no disruption to its products or services. The company is collaborating with ShipMonk on the investigation, confirming that the partner has secured and strengthened the affected systems. Trezor continues to notify customers directly to keep them informed and vigilant. For assistance, users are encouraged to contact Trezor’s support chat.
This breach underscores the critical importance of robust data protection measures and the need for companies to ensure that their third-party partners adhere to stringent security protocols. Customers should remain vigilant against potential phishing attempts and adopt best practices to safeguard their personal information.