TechNewsReel
Live

Trezor Shipping Partner Breach Exposes Data of 13,689 Customers

Unauthorized access to ShipMonk systems leaked physical addresses and contact details of hardware wallet buyers.

TechNewsReel Newsroom · August 13, 2026

Hardware wallet manufacturer Trezor has disclosed a data breach involving its third-party shipping provider, ShipMonk, which exposed the personal information of approximately 13,689 customers. While the company confirmed that its own internal systems and the security of the hardware wallets themselves remain intact, the leak of physical addresses for cryptocurrency users creates a significant security risk.

According to Trezor, the breach occurred after unauthorized actors gained access to ShipMonk's systems. The impact varied among the affected user base: 11,742 customers suffered full exposure, including their full names, email addresses, phone numbers, and shipping addresses. An additional 1,947 customers experienced partial exposure, with only their names, cities, and email addresses leaked. The breach impacted a global customer base, specifically affecting users in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.

The Logistics Gap

Trezor utilizes ShipMonk as a logistics partner to manage storage and shipping across several international markets. To mitigate the risks associated with third-party data handling, Trezor maintains a strict 90-day data storage policy. This policy requires partners to either delete or anonymize order data once the window expires. This internal safeguard limited the scope of the current breach, ensuring that only recent orders were compromised rather than the company's entire historical customer database.

Heightened Phishing Risks

Although private keys and device security were not compromised, the nature of the leaked data is particularly sensitive for the cryptocurrency community. The exposure of physical shipping addresses and contact details for verified hardware wallet owners allows bad actors to launch highly targeted, sophisticated phishing campaigns. These may include fraudulent physical mail or impersonation attempts designed to trick users into revealing their recovery seeds or transferring funds.

In a statement on its official blog, Trezor noted that while the devices are secure, affected customers could see an increase in phishing attempts. The company highlighted the rarity of the event, stating this is the first time since its founding in 2013 that a breach has exposed customer phone numbers and shipping addresses.

Monitoring the Aftermath

Users in the affected regions are advised to remain vigilant against unsolicited communications. While Trezor has confirmed that its core infrastructure was not breached, the incident underscores the persistent vulnerability of the "last mile" in the secure hardware supply chain. Industry observers will be watching to see if other logistics partners used by security firms face similar unauthorized access issues.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.