
On August 13, hardware wallet manufacturer Trezor reported a data breach affecting 13,689 users. The breach was caused by a hack of its logistics partner, ShipMonk.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
— Trezor (@Trezor) August 13, 2026
The ShipMonk team informed Trezor of unauthorized access to its systems on August 10. The attackers accessed order information from May 10 to August 8.
Preliminary data indicates that customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal were affected. Personal information of 11,742 customers was fully compromised, while 1,947 individuals had their names, cities, and email addresses exposed.
“This is the first incident since Trezor’s founding in 2013 where customer phone numbers and delivery addresses were exposed,” company representatives stated.
They also warned of potential increases in phishing attacks. Trezor has sent notifications to all affected users.
The impact of the incident was limited due to Trezor’s data retention policy, which requires logistics partners to delete or anonymize order information 90 days after delivery. As a result, older purchase data was no longer present in ShipMonk’s systems.
ShipMonk stated that it has enhanced security measures for the compromised systems. Trezor continues to investigate the breach.
The company also announced the Anonymous Delivery service, allowing customers to pick up devices from lockers, receive packages in plain packaging, and ensure delivery data is not retained. The service is expected to launch in the EU by September and in the US by the end of 2026.
Earlier in August, hardware wallet manufacturers Trezor and Foundation warned users about phishing attacks following the Coldcard incident.
