Hardware wallet maker Trezor warned Thursday that a shipping partner breach exposed personal data of 13,689 customers, with phishing attempts expected to follow.
According to a Trezor blog post, shipping partner ShipMonk informed Trezor on August 10 that an unauthorized actor accessed customer order data.
The breach affects customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10 and August 8, 2026.
The exposed data includes full names, shipping addresses, phone numbers, and email addresses. Of the 13,689 affected customers, 11,742 had full exposure across all four fields while 1,947 had partial exposure limited to name, city, and email.
Trezor’s 90-day data deletion policy limited the damage. Any customer who received an order before May 10 had their data already deleted from ShipMonk’s systems before the breach occurred.
Trezor confirmed that the incident did not compromise its devices or internal systems and said they remain fully secure.
The real risk is that attackers now have enough personal information to run convincing phishing campaigns by email, phone call, or physical mail, potentially impersonating Trezor, banks, or crypto exchanges.
Trezor’s guidance for affected customers:
All affected customers received a notification from help@trezor.io. Trezor said customers who did not receive that email are not affected.
Trezor said it is working directly with ShipMonk to determine what attackers accessed and how they breached the system.
ShipMonk has secured the affected systems and tightened its security following the incident.
Trezor noted this is the first breach in the company’s history since its founding in 2013 to expose customer phone numbers and shipping addresses.
The company is also working on an Anonymous Delivery option that uses locker pickup, neutral packaging, and automatic deletion of shipping identifiers after delivery, targeting EU availability by September 2026 and US availability by end of year.
Image: Shutterstock