Unauthorised access to logistics partner ShipMonk’s systems exposed the names and contact details of nearly 13,700 buyers. Trezor states that devices, private keys and wallet backups were not involved, but warns of targeted phishing risk.
Trezor has reported that unauthorised access to the systems of ShipMonk, one of its logistics partners, exposed the personal data of 13,689 customers. According to the notice published by the company, the investigation into the breach is still ongoing.
For 11,742 individuals, the exposed data includes full name, email address, phone number and shipping address. A further 1,947 customers experienced a partial exposure of name, city and email. Trezor notes that this second group may also include older orders, a detail it is still verifying with ShipMonk.
The main scope covers orders received between 10 May and 8 August 2026 in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. ShipMonk notified Trezor of the incident on 10 August. A 90-day data-retention limit, also imposed on fulfilment partners, reduced the number of orders present in the affected systems.
The breach did not affect Trezor’s own systems, devices, private keys or wallet backups. The concrete risk here is targeted phishing. Names, email addresses, phone numbers and physical addresses allow an attacker to craft more convincing messages, including impersonations of Trezor, a bank or an exchange. The company has contacted affected individuals directly from [email protected] and reminds users to never share a wallet backup or enter it on any website. The cases of the fake Ledger app and the LastPass supplier breach illustrate how the external supply chain can become an entry point.
Trezor is working on a more discreet delivery option using lockers, neutral packaging and automatic deletion of shipping identifiers, planned for the European Union by September 2026 and for the United States by the end of the year. The 90-day retention policy limited the number of records exposed, but the data already extracted remains outside the company’s control.





