13 Aug 2026 [security] [pinned]

13,689 Trezor customers affected by ShipMonk data breach

Trezor1 has just disclosed2 a massive data breach that affected their logistics partner ShipMonk3 on Monday (10 August 2026), which resulted in the full exposure of data for approximately 11,742 customers and partial exposure for at least 1,947 more:

[..] ShipMonk, informed us of unauthorized access to their systems containing customer data. This occurred due to a data breach. Investigation is ongoing. We’re extremely sorry to inform our community that customer personal information, including full names, phone numbers, email addresses, and shipping addresses, has been accessed by an unauthorized actor during this breach.

Incident Overview

* [Not Affected]:
 - all customers NOT contacted by help@trezor.io (check email)
* [Affected, full]: 
 - orders received within 90 days before August 8th, 2026
* [Affected, partial]:
 - TBD (may include older orders)
* [Exposed, full]:
 - name, email, phone number, shipping address for 11,742
* [Exposed, partial]:
 - name, city, email for ~1,947
* [Recommendations]:
 - watch for phishing attempts (fake emails, calls, letters, impersonation attempts)
 - never enter wallet backup on websites or share with anyone

According to the announcement, no system, product, or service was affected and Trezor devices remain entirely safe and secure.

Trezor has experienced community backlash in recent years over other issues4 and this latest incident - which is apparently the most serious data breach experienced by the company in the last 13 years - is bound to erode trust even more.

This is an ongoing story and the report will be updated when new information is available.