Trezor says ShipMonk breach exposed order data for 13,689 customers
The hardware-wallet maker said names, addresses, phone numbers and emails were accessed at its shipping provider, while its systems and devices were not compromised.
Trezor said a data breach at ShipMonk, one of its shipping providers, exposed personal order information for approximately 13,689 customers. The hardware-wallet maker’s Aug. 13 disclosure said the exposed data included names, shipping addresses, phone numbers and email addresses. Trezor said its own systems and devices were not compromised.
Trezor said ShipMonk informed it on Aug. 10 that an unauthorized actor had accessed systems containing customer data. The company reported full exposure for 11,742 customers and partial exposure for another 1,947, while warning that the latter group’s timing may include older orders and remains under review with ShipMonk.
The device is not the exposed control point
The distinction between order data and wallet secrets is central. Trezor said its systems were not compromised and that the device remains secure. The breach does not, on the company’s account, give an attacker a recovery phrase or direct control of a wallet. It does identify people who may own a hardware wallet, along with contact and delivery details that can make targeted impersonation more convincing.
Trezor said affected customers had been contacted separately and might see more phishing by email, phone or post. The company told users to cross-check messages against its official blog and channels and never enter a wallet backup online. Those are practical limits on the risk, but they do not undo the privacy loss or make every later message easy to identify.
The unresolved scope is part of the story
Trezor said the incident was constrained by its 90-day order-data retention policy, which it also requires fulfillment partners to follow. Its FAQ says ShipMonk held names, email addresses, order numbers, phone numbers and shipping addresses needed to deliver an order. The company also said the 1,947 partially exposed records may include orders outside the initial window and that it is verifying the timeframe.
Trezor said it is working with ShipMonk to establish exactly what happened and which data was accessed. It also plans an anonymous-delivery option, with a target of September 2026 in the European Union and the end of 2026 in the United States. The immediate watchpoint is narrower: whether the investigation changes the affected count or the data fields, and whether customers receive convincing follow-up scams tied to the leaked records.