Trezor shipping breach leaks customer data

Published July 31, 2026

A Trezor shipping partner's data breach exposed names, emails, phone numbers, and addresses of over 13,000 hardware wallet buyers. Attackers can now use this info to trick people into fake crypto scams.

Report priority
High
Victim
Anthropic

What is known

A third-party shipping company called ShipMonk lost access to Trezor's customer order data, leaking names, emails, phone numbers, and shipping addresses of buyers who ordered between May 10 and August 8, 2026.

What to do

Check if you ordered a Trezor wallet between May 10 and August 8, 2026, and if your name, email, phone, or address were exposed in the ShipMonk breach.

Monitor your email and messages for fake Trezor support scams. If you see a suspicious link, do not click it, visit Trezor's normal update channel instead.

Reported details

An attacker sends a fake Trezor support email to a victim's leaked email address. The email claims their wallet is locked and asks them to click a link to 'verify' it. The link goes to a phishing site that steals their crypto recovery seed.

This incident involved a third-party logistics provider, ShipMonk, which suffered unauthorized access to customer order data for Trezor hardware wallets. The breach exposed personal details, including names, email addresses, phone numbers, and shipping addresses, for approximately 13,689 customers who placed orders between May 10 and August 8, 2026. While Trezor's own systems, devices, or firmware were not compromised, attackers gained access to data used for phishing or social engineering attacks.

The affected records were limited to orders delivered within the last 90 days due to Trezor's data retention policy, which deletes or anonymizes order-related personal data after this period. ShipMonk stored only the necessary information for parcel fulfillment: name, email, order number, phone number, and shipping address. Trezor confirmed that affected customers received notification emails from help@.