Cryptelio

Trezor Reports Data Breach Affecting 13,689 Customers via Shipping Partner

Cryptelio Editorial Published 13 Aug 2026 · 15:01 UTC Updated 13 Aug 2026 · 16:32 UTC
Trezor Reports Data Breach Affecting 13,689 Customers via Shipping Partner

Trezor, a prominent hardware wallet manufacturer, announced on Thursday that a data breach at its shipping partner, ShipMonk, has compromised the personal information of 13,689 customers. The breach, which affected customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal, involved orders placed between May 10 and August 8, 2026.

The exposed data includes names, email addresses, phone numbers, and shipping information. Specifically, 11,742 customers experienced a full exposure of their personal details, while 1,947 customers had partial exposure, losing only their name, city, and email.

Trezor clarified that its own systems and devices were not compromised during the incident, and emphasized that its strict 90-day data retention policy limited the amount of information available to ShipMonk. The company has warned affected customers about potential phishing attempts and advised them to only use official Trezor channels for communications.

ShipMonk informed Trezor of the breach on August 10, revealing that an intruder had accessed systems containing customer records. Trezor has since reached out to those impacted, advising them to be vigilant against scams that could arise from the leaked information.

In light of this incident, Trezor reiterated the importance of safeguarding personal information and urged customers to avoid sharing their wallet backup details with anyone. The company is also planning to introduce an Anonymous Delivery option, aimed at enhancing customer privacy, which is expected to roll out in the EU by September and in the US by the end of 2026.

Updated 16:32 UTC

Trezor Data Breach Update

Trezor has confirmed that the personal details of 13,689 customers were compromised due to a data breach at its shipping partner, ShipMonk. The affected customers are from the UK, US, Sweden, Colombia, Brazil, Italy, and Portugal, and had ordered Trezor products between May 10 and August 8, 2026.

Details leaked include full names, physical addresses, phone numbers, and email addresses for nearly 12,000 customers, while almost 2,000 customers had their names, cities, and email addresses exposed.

Trezor has assured that its infrastructure, including devices and private keys, remains secure. The company has warned affected users to be vigilant against potential phishing scams.

Only customers who received a warning email from Trezor are impacted. Trezor is currently assessing the situation and has not yet made a decision regarding its partnership with ShipMonk.

To mitigate future risks, Trezor is implementing an "anonymous delivery" option and emphasizes its 90-day data policy, which allows for the deletion or anonymization of order data after delivery.

FAQ

What was the cause of the data breach affecting Trezor customers?

The data breach was caused by a security incident at Trezor's shipping partner, ShipMonk, which compromised the personal information of 13,689 customers.

What type of personal information was exposed in the breach?

The exposed data includes names, email addresses, phone numbers, and shipping information. Specifically, 11,742 customers had full exposure of their details, while 1,947 had partial exposure.

How many customers were affected by the data breach?

A total of 13,689 customers were affected by the data breach, with varying degrees of exposure to their personal information.

What measures is Trezor taking to protect its customers after the breach?

Trezor has warned affected customers about potential phishing attempts, advised them to use only official channels for communications, and is planning to introduce an Anonymous Delivery option to enhance customer privacy.

Will Trezor's own systems and devices be affected by the breach?

No, Trezor clarified that its own systems and devices were not compromised during the incident, and they have a strict 90-day data retention policy in place.

Related

Comments

Comments are moderated before publish.

No comments yet — be the first.

Comment as guest

Captcha