Trezor disclosed that unauthorized access at third-party logistics provider ShipMonk exposed customer order data for 13,689 hardware wallet buyers, affecting recent deliveries across the U.S., U.K., Sweden, Colombia, Brazil, Italy, and Portugal. The exposed information included full names, email addresses, phone numbers, and shipping addresses for 11,742 customers, while 1,947 others had more limited data exposed, such as name, city, and email address. Trezor said ShipMonk notified it of the incident after attackers accessed systems containing order records tied to shipments delivered between May 10 and Aug. 8, 2026.
Trezor said its own infrastructure, wallets, devices, and firmware were not compromised, but warned affected customers to expect phishing, impersonation, and possible physical-security risks because the leaked data links identities to hardware wallet purchases. The company said its 90-day data retention policy limited the scope because older records had already been deleted or anonymized, and it has notified impacted users by email while working with ShipMonk as the provider secures and hardens affected systems. Trezor also said it plans to roll out an Anonymous Delivery option, first in the EU and later in the U.S., to reduce future customer exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-10, ShipMonk informed Trezor that unauthorized access had occurred in systems containing customer data. The affected systems held order-fulfillment information for Trezor customers.
ShipMonk told affected customers that attackers exploited a vulnerability in the third-party analytics platform Metabase to access data tied to ShipMonk and its customers. ShipMonk said Metabase notified it on 2026-08-06, and that Metabase patched the flaw and invalidated active sessions.
The customer records later exposed in the ShipMonk incident were tied to orders delivered between 2026-05-10 and 2026-08-08. Trezor said the affected population consisted of recent shipments within that period.
Trezor announced plans for an Anonymous Delivery option intended to reduce future exposure of customer shipping data. The planned feature includes dedicated checkout, locker pickup, neutral packaging, generic sender details, and deletion of shipping identifiers after delivery.
Trezor said ShipMonk had secured and hardened the affected systems after the breach. Trezor also said it was working with ShipMonk to investigate what happened and determine exactly which data was accessed.
Trezor said it notified affected customers by email from help@trezor.io and warned them to expect phishing, spoofed calls, fraudulent letters, and impersonation attempts. The company said customers who did not receive the notification email were not part of the exposed set.
Trezor said 11,742 customers had names, email addresses, phone numbers, and shipping addresses exposed, and an additional 1,947 customers had names, home cities, and email addresses exposed. It also said some of the additional group may have placed orders before 2026-05-10, indicating the exposure may extend beyond the previously identified shipment window.
Trezor disclosed that unauthorized access at third-party logistics provider ShipMonk exposed fulfillment-related customer data for about 13,689 customers. Trezor said its own infrastructure, wallets, devices, and firmware were not compromised.
SecurityWeek reported that the extortion group ShinyHunters claimed responsibility for an attack on Metabase and leaked data allegedly stolen from Metabase on Wednesday. This introduced a new attribution-related development connected to the ShipMonk/Trezor exposure, though responsibility for the ShipMonk breach itself remained unconfirmed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcecyberveille.ch
Open sourcescworld.com
Open sourcetheregister.com
Open sourcebleepingcomputer.com
Open sourcethedefiant.io
Open sourcecybersecuritynews.com
Open sourcetrezor.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.