On August 13, Trezor, the hardware wallet manufacturer, disclosed that a data breach had compromised the personal information of 13,689 users. This breach was attributed to a hack of their logistics partner, ShipMonk.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
— Trezor (@Trezor) August 13, 2026
ShipMonk informed Trezor about unauthorized access to their systems on August 10. The breach involved order information from May 10 to August 8.
Preliminary reports indicate that customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal were affected. A total of 11,742 individuals had their complete personal details stolen from ShipMonk's database, while an additional 1,947 customers had partial information compromised, including names, cities, and email addresses.
„This is the first incident since Trezor's inception in 2013 where a breach has revealed customers' phone numbers and delivery addresses,” the company representatives stated.
They also cautioned about a potential increase in phishing attacks. Trezor has sent notifications to all users impacted by the breach.
The extent of the incident was mitigated due to the company’s data retention policy, which mandates that logistics partners delete or anonymize order information after 90 days post-delivery. Consequently, details from earlier purchases were no longer present in ShipMonk's systems.
ShipMonk announced that they have enhanced the security of the compromised systems. Meanwhile, Trezor is continuing its investigation.
The company has also introduced a new service called Anonymous Delivery, which allows customers to pick up devices from lockers, receive packages in plain packaging, and ensures that delivery data is not retained. This service is set to launch in the European Union by September and in the US by the end of 2026.
In August, hardware wallet manufacturers Trezor and Foundation had already warned users about phishing attacks in light of the Coldcard incident.
