Popular hardware wallet manufacturer Trezor disclosed a third-party security incident on August 13, revealing that personal information belonging to 13,689 customers was exposed following unauthorized access to systems operated by its logistics partner, ShipMonk. ShipMonk initially notified Trezor of the breach after discovering that an unauthorized actor had accessed order fulfillment systems containing customer delivery data.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
— Trezor (@Trezor) August 13, 2026
The security incident impacts customers who received a trezor.io order within the 90-day window prior to August 8, 2026, across the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor emphasized that its own internal systems were not compromised, leaving hardware devices, private keys, and wallet backups completely safe.
Details of the ShipMonk System Compromise
Logistics provider ShipMonk manages product storage and physical order fulfillment for Trezor across multiple international jurisdictions, requiring customer contact details to process shipments. For 11,742 affected customers, the exposed data corresponds directly to what is required for parcel delivery: full names, physical addresses, phone numbers, and email addresses. A further 1,947 customers suffered a smaller set of exposed data consisting of names, cities, and email addresses.
Trezor stated that the scope of the breach was strictly limited by its 90-day data policy, which fulfillment partners are contractually required to enforce. Under this framework, customer order data is automatically deleted or anonymized 90 days after delivery. Without this policy in place, the breach would have covered years of customer orders instead of three months. All affected individuals were notified via email today from help@trezor.io, with Trezor confirming that customers who did not receive an email were not impacted.
ShipMonk has since secured the affected systems, while Trezor has notified the relevant data protection authority and remains in contact with ShipMonk to gather further details on the incident. Notably, this represents the first time in Trezor’s operating history since 2013 that customer phone numbers and physical delivery addresses have been exposed through a third-party breach.
Rising Threats of Targeted Phishing and Physical Attacks
While hardware wallets and recovery seeds remain technically untouched, Trezor cautioned that the primary threat arising from the exposed data is phishing conducted via email, phone, or physical post. Malicious actors frequently leverage names, home addresses, phone numbers, and email accounts to craft convincing impersonation attacks, pretending to represent Trezor, banks, or cryptocurrency exchanges.
Physical mail phishing presents a particularly severe security concern for hardware wallet owners. Previous industry campaigns have involved fake letters directing recipients to malicious websites using embedded QR codes under the guise of mandatory security updates or account verification checks. These deceptive portals prompt users to input their recovery seeds, granting attackers complete control over the victim’s funds. Trezor reminded users that no representative from Trezor will ever ask for a wallet backup, urging customers to treat urgent requests for information with high suspicion.
To reduce data exposure for future purchases, Trezor advised customers to use burner email addresses, pay via digital assets, and utilize postal boxes where feasible. Additionally, the company announced plans to roll out an “Anonymous Delivery” service across the European Union by September 2026, with a US rollout planned by year-end, featuring neutral packaging, locker collection, and automatic deletion of tracking identifiers post-delivery.
Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.