Trezor Discloses ShipMonk Data Breach Affecting 13,700 Customers Across Seven Countries

13-Aug-2026 mpost.io
Trezor Discloses ShipMonk Data Breach Affecting 13,700 Customers Across Seven Countries

Hardware wallet manufacturer Trezor has disclosed a data breach at its third-party logistics partner ShipMonk that exposed the personal information of approximately 13,700 customers across seven countries. 

The incident, which the company described as its first exposure of customer phone numbers and shipping addresses since its founding in 2013, affects new users in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders within the 90 days prior to August 8, 2026.

According to Trezor, unauthorized actors accessed ShipMonk’s systems around August 10, 2026, compromising order records that included full names, shipping addresses, phone numbers, and email addresses. In total, 11,742 customers suffered full exposure of these details, while an additional 1,947 experienced partial exposure limited to name, city, and email. 

The company emphasized that its own systems and hardware devices were not compromised, and that the breach scope was limited by a strict 90-day data retention policy requiring fulfillment partners to delete or anonymize order records after delivery.

“We have some difficult news to share,” Trezor stated in its original announcement. “Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data.” 

All affected users have been notified directly via email. Trezor cautioned that leaked personal details could fuel more sophisticated phishing campaigns, with attackers potentially impersonating banks, cryptocurrency exchanges, or Trezor itself to extract sensitive information.

Anonymous Delivery and Enhanced Privacy Measures

In response to the incident, Trezor is accelerating the development of an “Anonymous Delivery” service designed to sever the link between hardware wallet purchases and customers’ real-world identities. 

The option, targeted for launch in the European Union by September 2026 and in the United States by year-end, will feature a dedicated checkout flow allowing users to register under a nickname or label ID, collect parcels from automated lockers, and receive orders in unbranded packaging with generic sender labels. Carriers will communicate pickup codes exclusively via email or SMS, with shipping identifiers automatically deleted after delivery.

Trezor advised all customers to remain vigilant against phishing attempts via email, phone, or post, and to never enter wallet recovery phrases on websites or share them with third parties. The company confirmed that ShipMonk has secured the affected systems and hardened its security posture following the incident, while Trezor continues to investigate the full circumstances of the breach.

The post Trezor Discloses ShipMonk Data Breach Affecting 13,700 Customers Across Seven Countries appeared first on Metaverse Post.

Also read: Deribit Broker Dealer Licence Opens Coinbase Liquidity to Clients
WHAT'S YOUR OPINION?
Related News