Trezor Shipping Partner Breach Exposes Data of 13,689 Customers
A security incident at logistics provider ShipMonk leaked personal details of hardware wallet buyers, raising phishing risks.
A data breach at ShipMonk, a third-party logistics partner for Trezor, has exposed the personal information of approximately 13,689 customers. While the security of the hardware wallets themselves remains intact, the leak of customer identities creates a significant opening for targeted social engineering attacks.
According to Trezor, the breach resulted from unauthorized access to ShipMonk's systems and affected orders placed between May 10 and August 8, 2026. The exposure varied by customer: 11,742 individuals suffered full exposure of their names, emails, phone numbers, and physical addresses, while 1,947 customers had partial exposure involving their names, cities, and emails. The incident impacted a global user base, specifically affecting customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal.
The Role of Data Retention
Trezor utilizes ShipMonk to manage the storage and global distribution of its products. To mitigate the risks associated with third-party data handling, Trezor enforces a strict 90-day data storage policy. This mandate requires logistics partners to either delete or anonymize customer data 90 days after a product has been delivered. Because of this policy, the scope of the ShipMonk breach was limited to recent orders, preventing the exposure of years of historical customer data.
Heightened Phishing Risks
Although Trezor confirmed that its own internal systems, hardware wallets, and private keys were not compromised, the nature of the leaked data is particularly sensitive. The knowledge that a specific individual owns a cryptocurrency hardware wallet makes them a high-value target for malicious actors.
By combining physical addresses and phone numbers with the confirmation of wallet ownership, attackers can craft highly sophisticated phishing campaigns. These may include fraudulent delivery notifications or social engineering attempts designed to trick users into revealing their recovery seeds or granting access to their funds. Trezor warned that affected customers "might be targeted by more sophisticated phishing attempts" as a direct result of the leak.
Next Steps for Users
Users who placed orders during the affected window should remain vigilant against unsolicited communications. Security experts typically recommend that hardware wallet owners never share their recovery seeds with anyone and avoid clicking links in emails or texts claiming to be from shipping providers or wallet manufacturers.
Trezor continues to emphasize that the core security of the device is unaffected, but the incident highlights the persistent vulnerability of the "last mile" of the supply chain, where personal data is often shared with third-party vendors.