
Shipping partner loses customers' personal data
Trezor confirmed on 10 August 2026 that a data breach at its shipping provider ShipMonk had compromised information belonging to a total of 13,689 customers, according to the Financial Times. The breach affects customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between 10 May and 8 August this year.
It is worth noting that ShipMonk holds SOC 2 Type II certification – a recognised security standard for data service providers. Despite this, attackers managed to gain access and extract sensitive customer information.

Two different levels of exposure
Trezor distinguishes between two categories of affected customers. Of the nearly 14,000 customers, 11,742 experienced what the company describes as "full exposure": their name, email address, phone number, and complete delivery address have all fallen into the wrong hands. The remaining 1,947 customers suffered "partial exposure", limited to name, city, and email address.
Not since Trezor's founding in 2013 have phone numbers and delivery addresses been exposed in a data breach, according to the company's own communications. Trezor stresses that its internal systems, devices, and customers' wallet data are unaffected.

Third major security breach in three years
This incident is not an isolated case. In January 2024, a third-party support system was compromised, exposing the contact information of up to 66,000 Trezor users. At least 41 of these were subsequently contacted directly by attackers attempting to trick them into revealing their recovery phrases, according to available information about the incident. In March 2022, Trezor's newsletter provider Mailchimp was hacked, and the stolen email lists were used to send out highly convincing phishing emails.
Heightened phishing risk in the wake of the breach
Security experts point out that the combination of name, phone number, and physical address makes future fraud attempts far harder to detect. Attackers can now contact affected customers via email, SMS, phone, or even regular mail – presenting personal information that lends an air of legitimacy.
Trezor states that the company is working on an "Anonymous Delivery" service, which is planned to be available in the EU by September 2026 and in the United States before the end of the year. In the meantime, the company encourages customers to use email addresses that are not linked to their real names, and to pay with cryptocurrency where possible.
What should affected customers do?
For the more than 13,600 customers affected by the latest breach, the advice is clear: never share your recovery phrase with anyone, and treat all unsolicited contact claiming to come from Trezor with extreme scepticism. The company will never reach out via SMS, WhatsApp, Telegram, phone, or physical letter. Any approach through these channels should be reported and blocked immediately.
With bitcoin trading around $63,000 and a Fear & Greed Index of 29 out of 100 – indicating fear in the market – security awareness has rarely been more important for crypto holders.
This article was written using large language models under editorial supervision by Aprex. Content is source-verified and auditable. Read our method →