Veuillez noter : nos articles de blog ne sont actuellement disponibles qu’en anglais.

News

Recent customer data exposed in shipping provider incident

Trezor Team
Trezor Team
Lecture de 7 min
Aug 13, 2026

Summary

ShipMonk, one of Trezor’s shipping providers, has experienced a data breach that exposed sensitive customer order data, including full names, shipping addresses, phone numbers, and email addresses. Trezor devices are secure, but affected customers could experience an increase in phishing attempts. This data breach can potentially affect new customers who received an order from the following countries: US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between 10th of May and 8th of August 2026. If you are unsure whether you were affected, please check your email inbox for a message from [email protected]

Update: According to our newest findings, the 1,947 customers whose exposure was limited only to name, city and email address (without the shipping address) may include older orders. We are verifying this information and the timeframe with ShipMonk.

ShipMonk data breach

On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data. This occurred due to a data breach. Investigation is ongoing.

We’re extremely sorry to inform our community that customer personal information, including full names, phone numbers, email addresses, and shipping addresses, has been accessed by an unauthorized actor during this breach.

The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947* customers with partial exposure (name, city, email). The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy).

All affected customers have been contacted separately by email. If you did not receive an email from [email protected] then you are not affected by this data breach.

To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts.

Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor.

Please:

  • Be suspicious of any communication that prompts immediate action or asks for personal information.
  • Always cross-reference email and web content with official Trezor communications on our social channels and our blog.

Never enter your wallet backup on a website or share it with anyone.

This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses. We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected.

If you have concerns or need further assistance, please reach out to our customer support team here.

How to limit the data sharing when ordering with Trezor

While we can’t completely eliminate data sharing when shipping physical products globally, there are options you can use to order more privately…

  1. When ordering, use an anonymous email address that is not linked to your real identity.
  2. Consider paying with crypto instead of using a credit card. If that’s not possible, it’s recommended to use disposable digital cards for online purchases.
  3. Use a P.O. Box if possible to limit address exposure (although an ID will still likely be needed for collection, and your data will be stored by USPS).
  4. Anonymous Delivery (coming soon) lets you receive your hardware wallet more privately by using a dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery.

We aim to make this shipping option available in the EU by September 2026 and in the US by the end of 2026.

Your questions, answered (FAQs)

Who is ShipMonk and why did they have my data?

ShipMonk is the logistics partner that stores our products and ships orders to customers in the US, UK and several other countries. To deliver a parcel, they need your name, shipping address, phone number (required by delivery companies), and email address. That is the only reason they hold any of your data, and under our policy they must delete or anonymize it 90 days after delivery.

What specific data was exposed?

ShipMonk holds what is needed to deliver a parcel: name, email address, order number, phone number, and shipping address. Only orders received within 90 days before August 8th, 2026, were affected, as older data had already been deleted.

Has this breach affected me? How can I know if my contact details were among those exposed?

If you received our notification email (from: [email protected]) regarding the security incident, your contact details have been among those exposed.

My order is older than 90 days. Why was my data involved?

We are sorry. According to our newest findings, the 1,947 customers whose exposure was limited only to name, city and email address (without the shipping address) may include older orders. We are verifying the exact timeframe with ShipMonk and will update this answer as soon as we have confirmation. If you received our notification email from [email protected], your details were among those exposed, and we are sorry that this happened.

What should I do if I’m affected by this breach?

We recommend being especially vigilant of an increase in sophisticated phishing events across all platforms.

Never share your wallet backup or type it in online.

How many customers are affected by this incident?

Approximately 13,689 customers are affected. The number is limited by our retention policy: we require our partners to delete or anonymize order data 90 days after delivery, so older orders were no longer held in ShipMonk systems and could not be exposed.

Why do you wait 90 days to delete or anonymize customer data?

After 90 days we delete or anonymize all customer data related to a purchase on our Trezor eShop. We chose 90 days because it is the shortest window that still covers the whole life of an order — delivery, returns, and any refund or replacement. After that we have no reason to keep your address or phone number.

How has this breach impacted Trezor's operations or services?

This was a breach at ShipMonk, our third-party fulfillment partner. No Trezor system, product, or service was affected, and our operations continue as normal. Trezor devices remain entirely safe and secure. The one real impact is that affected customers may see more phishing attempts by email, phone, or post, so please stay vigilant and follow the security best practices on the Trezor website.

What security steps have you taken?

We are in direct contact with ShipMonk to establish exactly what happened and which data was accessed. ShipMonk has secured the affected systems and hardened its security after the incident. We are also notifying affected customers directly so they can watch out for phishing.

Trezor Team
Trezor Team
Articles written by Trezor's team members.

Rejoindre la newsletter Trezor !

Recevez des offres exclusives, des actualités concernant nos produits, et des analyses crypto directement dans votre boîte de réception.
En cliquant sur "S'abonner", vous acceptez que Trezor Company s.r.o. utilise votre e-mail uniquement pour vous envoyer sa newsletter. Vous pouvez vous désabonner à tout moment en utilisant le lien approprié dans chaque e-mail. Pour voir comment nous gérons vos données, veuillez consulter la Politique de confidentialité de Trezor.