A data breach at Trezor‘s logistics partner, ShipMonk, exposed order data for 13,689 customers across seven countries. The incident affected 11,742 buyers whose names, email addresses, phone numbers, and shipping addresses were compromised, plus 1,947 whose names, cities, and email addresses were taken. Trezor confirmed that the exposed records came from orders placed between May 10 and August 8, 2026, and that hardware wallets, private keys, and wallet backups were not affected. The company has warned affected users to expect an increase in phishing attempts, following a similar incident previously faced by rival Ledger.
Trezor disclosed today that a data breach at its fulfillment partner ShipMonk has exposed order data for 13,689 customers across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
The breach compromised 11,742 customers whose names, email addresses, phone numbers, and shipping addresses were taken, plus 1,947 whose names, cities, and email addresses were exposed. Order numbers were also included in the leaked data.
“Our systems were not compromised, and your Trezor device is secure,” the company stated, adding that hardware wallets, private keys, and wallet backups were not affected. A 90-day data storage policy kept older orders out of the exposed set.
Trezor told customers to treat any communication demanding immediate action or requesting personal information as “suspicious.” The company warned that affected customers “could experience an increase in phishing attempts.”
The phishing risk follows a comparable incident at rival Ledger, where scammers used leaked order data to send emails claiming a merger and requesting recovery phrases. Trezor said it is investigating and will publish updates on its blog.
The company also mentioned building an Anonymous Delivery option with neutral packaging and automatic deletion of shipping identifiers. This marks the third time Trezor customers have been reached through third-party vendors, following breaches at MailChimp in 2022 and a support ticketing portal in 2024.
