Shipping partner loses customers' personal data

Trezor confirmed on 10 August 2026 that a data breach at its shipping provider ShipMonk had compromised information belonging to a total of 13,689 customers, according to the Financial Times. The breach affects customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between 10 May and 8 August this year.

It is worth noting that ShipMonk holds SOC 2 Type II certification – a recognised security standard for data service providers. Despite this, attackers managed to gain access and extract sensitive customer information.

11 742
Customers with full exposure
1 947
Customers with partial exposure
Nearly 14,000 Trezor customers hit by data breach - Bilde 1

Two different levels of exposure

Trezor distinguishes between two categories of affected customers. Of the nearly 14,000 customers, 11,742 experienced what the company describes as "full exposure": their name, email address, phone number, and complete delivery address have all fallen into the wrong hands. The remaining 1,947 customers suffered "partial exposure", limited to name, city, and email address.

Not since Trezor's founding in 2013 have phone numbers and delivery addresses been exposed in a data breach, according to the company's own communications. Trezor stresses that its internal systems, devices, and customers' wallet data are unaffected.

This is the first time since 2013 that Trezor customers' phone numbers and delivery addresses have ended up in the hands of hackers.
Nearly 14,000 Trezor customers hit by data breach - Bilde 2

Third major security breach in three years

This incident is not an isolated case. In January 2024, a third-party support system was compromised, exposing the contact information of up to 66,000 Trezor users. At least 41 of these were subsequently contacted directly by attackers attempting to trick them into revealing their recovery phrases, according to available information about the incident. In March 2022, Trezor's newsletter provider Mailchimp was hacked, and the stolen email lists were used to send out highly convincing phishing emails.

Heightened phishing risk in the wake of the breach

Security experts point out that the combination of name, phone number, and physical address makes future fraud attempts far harder to detect. Attackers can now contact affected customers via email, SMS, phone, or even regular mail – presenting personal information that lends an air of legitimacy.

Trezor states that the company is working on an "Anonymous Delivery" service, which is planned to be available in the EU by September 2026 and in the United States before the end of the year. In the meantime, the company encourages customers to use email addresses that are not linked to their real names, and to pay with cryptocurrency where possible.

What should affected customers do?

For the more than 13,600 customers affected by the latest breach, the advice is clear: never share your recovery phrase with anyone, and treat all unsolicited contact claiming to come from Trezor with extreme scepticism. The company will never reach out via SMS, WhatsApp, Telegram, phone, or physical letter. Any approach through these channels should be reported and blocked immediately.

With bitcoin trading around $63,000 and a Fear & Greed Index of 29 out of 100 – indicating fear in the market – security awareness has rarely been more important for crypto holders.