Trezor discloses data breach affecting nearly 14,000 customers
Trezor, a hardware wallet manufacturer, disclosed a data breach affecting nearly 14,000 customers due to a hack of its shipping provider, ShipMonk. The attackers accessed customer order data including full names, shipping addresses, email addresses, and phone numbers. The breach impacts customers from multiple countries who received orders between May 10 and August 8, 2026. Trezor's own systems and devices were not compromised, but affected customers may face increased phishing attempts using the stolen data. The company warns users to be vigilant against scams impersonating banks, crypto exchanges, or Trezor itself.
AI Analysis
Technical Summary
The data breach occurred after unauthorized access to ShipMonk's systems, Trezor's shipping and logistics partner, exposed customer order information. Specifically, 11,742 customers had full exposure of name, email, phone number, and shipping address, while 1,947 customers had partial exposure (name, city, email). Trezor confirmed that its internal systems and hardware wallets remain secure and unaffected. The breach is limited to customer data handled by the third-party logistics provider. Trezor advises affected customers to be cautious of phishing attempts leveraging the leaked personal information. This incident follows a previous breach in January 2024 involving Trezor's support ticketing portal.
Potential Impact
The breach exposed personally identifiable information (PII) of nearly 14,000 customers, including full names, shipping addresses, email addresses, and phone numbers for most affected individuals. This data exposure increases the risk of targeted phishing attacks, social engineering, and impersonation scams against these customers. However, Trezor's hardware wallets and internal systems were not compromised, so the security of cryptocurrency assets stored on Trezor devices remains intact. The breach does not impact Trezor's operational services but poses a privacy risk to affected customers.
Mitigation Recommendations
Trezor has confirmed that its systems and devices are secure and were not compromised. Customers affected by the breach should remain vigilant against phishing attempts and avoid responding to unsolicited requests for personal information or recovery seeds. There is no indication that Trezor devices need to be replaced or that users must change wallet credentials. Monitoring communications for suspicious activity and verifying the authenticity of messages purportedly from Trezor or financial institutions is recommended. No direct patch or fix is applicable since the breach occurred via a third-party logistics provider.
Affected Countries
United States, United Kingdom, Sweden, Colombia, Brazil, Italy, Portugal
Trezor discloses data breach affecting nearly 14,000 customers
Description
Trezor, a hardware wallet manufacturer, disclosed a data breach affecting nearly 14,000 customers due to a hack of its shipping provider, ShipMonk. The attackers accessed customer order data including full names, shipping addresses, email addresses, and phone numbers. The breach impacts customers from multiple countries who received orders between May 10 and August 8, 2026. Trezor's own systems and devices were not compromised, but affected customers may face increased phishing attempts using the stolen data. The company warns users to be vigilant against scams impersonating banks, crypto exchanges, or Trezor itself.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The data breach occurred after unauthorized access to ShipMonk's systems, Trezor's shipping and logistics partner, exposed customer order information. Specifically, 11,742 customers had full exposure of name, email, phone number, and shipping address, while 1,947 customers had partial exposure (name, city, email). Trezor confirmed that its internal systems and hardware wallets remain secure and unaffected. The breach is limited to customer data handled by the third-party logistics provider. Trezor advises affected customers to be cautious of phishing attempts leveraging the leaked personal information. This incident follows a previous breach in January 2024 involving Trezor's support ticketing portal.
Potential Impact
The breach exposed personally identifiable information (PII) of nearly 14,000 customers, including full names, shipping addresses, email addresses, and phone numbers for most affected individuals. This data exposure increases the risk of targeted phishing attacks, social engineering, and impersonation scams against these customers. However, Trezor's hardware wallets and internal systems were not compromised, so the security of cryptocurrency assets stored on Trezor devices remains intact. The breach does not impact Trezor's operational services but poses a privacy risk to affected customers.
Defensive Guidance
Trezor has confirmed that its systems and devices are secure and were not compromised. Customers affected by the breach should remain vigilant against phishing attempts and avoid responding to unsolicited requests for personal information or recovery seeds. There is no indication that Trezor devices need to be replaced or that users must change wallet credentials. Monitoring communications for suspicious activity and verifying the authenticity of messages purportedly from Trezor or financial institutions is recommended. No direct patch or fix is applicable since the breach occurred via a third-party logistics provider.
Affected Countries
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/","fetched":true,"fetchedAt":"2026-08-13T15:26:18.884Z","wordCount":696}
Threat ID: 6a7de21abf8831d539625b40
Added to database: 08/13/2026, 15:26:18 UTC
Last enriched: 08/13/2026, 15:26:36 UTC
Last updated: 08/14/2026, 01:27:20 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.