← Blog

Trezor ShipMonk Breach: Impact Hits ~81K Customers

Share on X

September 2026 update: Hardware wallet maker Trezor says the August ShipMonk fulfillment breach now reaches roughly 81,000 customers after an additional ~67,000 U.S. buyers from a 2019–2021 order window were found still sitting in ShipMonk’s systems. Devices, seed phrases, and Trezor’s own infrastructure remain untouched per the company. The sting is logistics PII—names, emails, phones, shipping addresses, order numbers—plus a retention failure Trezor says it had written assurances would never happen. Canonical record: trezor-shipmonk2026.

When Trezor first went public on August 13, the count was 13,689. That number was supposed to be the ceiling. A 90-day delete-or-anonymize rule with fulfillment partners was meant to keep older eShop orders out of ShipMonk’s reach. The September correction shows how fragile that promise was: legacy U.S. records from November 2019 through August 2021 were still there when attackers got in.

What happened

On August 10, 2026, ShipMonk told Trezor that an unauthorized party had accessed systems holding customer order data. Trezor emailed affected buyers and published its shipping-provider notice on August 13. The first cohort covered customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal whose orders landed roughly May 10–August 8, 2026—the window ShipMonk should still have held under the 90-day retention deal.

Within that first disclosure, Trezor split exposure into two buckets: 11,742 customers with full details (name, email, phone, shipping address) and 1,947 with partial details (name, city, email). An August 14 clarification added that the partial set could include older orders. Even then, the public story still centered on ~13.7k people.

On September 2, 2026, ShipMonk informed Trezor the breach was larger. Trezor’s September 4 blog update and follow-on reporting by BleepingComputer put another approximately 67,000 U.S. customers in scope—people who ordered between November 2019 and August 2021. Combined impact is about 81,000 (BreachHistory catalogs 80,689). Trezor says every newly identified customer has been emailed from [email protected]. No notification email means you are not in the exposed set, per the company.

The retention failure behind the jump

This is not a quiet count revision. Trezor’s update is blunt: throughout the ShipMonk relationship it “repeatedly requested and received written assurance confirming the deletion of the data,” matching contract language, Trezor’s data policy, and prior communications. Despite those assurances, the 2019–2021 U.S. order data was still present when the intrusion happened.

That matters beyond this one brand. Hardware-wallet retailers lean hard on third-party fulfillment. Privacy pages that promise short retention only work if partners purge on schedule and if analytics mirrors do not keep forever copies. Written confirmation without purge evidence is theater. Trezor’s disappointment reads like a vendor-management case study written in customer blood—metaphorically speaking, and with physical-security risk that is uncomfortably literal.

What data was exposed

Across both cohorts, the logistics fields at stake are consistent:

  • Full name
  • Email address
  • Phone number
  • Shipping address (full exposure sets)
  • Order number

The September legacy cohort is described as full exposure for those ~67,000 U.S. customers—name, email, phone, shipping address, and order number. Parcel contents were not part of the leak. Payment-card data is not in the ShipMonk order dataset Trezor describes for this incident.

What was not exposed, according to Trezor: device firmware integrity, seed phrases / wallet backups, private keys, and Trezor corporate systems. The company repeats that its own stack was not compromised and that Trezor devices remain secure. Do not confuse a shipping-provider PII breach with a Secure Element failure. They are different problems with different playbooks.

How the attack reportedly worked

Trezor has not published a forensic root-cause of its own. Customer notices from ShipMonk, reviewed by BleepingComputer, attribute unauthorized access to a vulnerability in third-party analytics platform Metabase. Metabase had already disclosed a critical SQL-injection path abused against customer instances in a broader 2026 data-theft campaign. Framework and Tally are among other brands that notified customers after Metabase-instance compromise.

BleepingComputer separately reported that ShipMonk received extortion emails from the ShinyHunters gang. Extortion mail does not by itself prove which group ran the Metabase exploit, but it fits the pattern of analytics-tool break-ins followed by pressure campaigns. For readers: treat Metabase and ShinyHunters as the trade-press path for ShipMonk’s intrusion, not as claims that Trezor’s wallets were cracked.

Why address leaks hurt hardware-wallet buyers

Crypto phishing after Ledger’s historical e-commerce leaks trained attackers to pair “you own a cold wallet” with urgent seed-phrase lures. Full home addresses raise the stakes further. Postal letters on fake letterhead, courier SMS about “customs fees,” voice calls that already know your order number, and doorstep pretexting become practical once someone knows a household bought a Trezor.

Trezor’s September update explicitly flags phishing and physical security risk. That pairing is the story. Scammers do not need to break the device. They need fear, urgency, and enough PII to sound like support, a bank, an exchange, or a courier. The 2024 Trezor support-portal breach—roughly 66,000 names and emails—was later used for seed-phishing. This ShipMonk dump adds phones and street addresses for tens of thousands more households. Assume the social-engineering toolkit gets sharper, not quieter.

Who is at risk

Recent buyers (May 10–August 8, 2026): Customers in the seven named countries who received ShipMonk-fulfilled parcels in that window, plus anyone already emailed in August. Full-exposure households should treat street address and phone as attacker-known. Partial-exposure customers (name/city/email) still face phishing even without a full street line in the first dump description.

Legacy U.S. buyers (November 2019–August 2021): Roughly 67,000 additional customers whose order data ShipMonk failed to delete. Many of these people had every reason to believe their fulfillment PII aged out years ago. If you ordered a Trezor to a U.S. address in that span and received a September [email protected] notice, you are in the expanded set.

Household members and mailrooms: Family who answer the door, office receiving desks, and shared PO Boxes can become the soft target even when the device owner is careful. Brief them. A courier scam aimed at “the Trezor order” does not need the owner on the phone.

Not automatically in scope: Buyers outside the windows and countries Trezor named, and anyone who never received [email protected] mail about this incident. Do not trust random “breach check” sites that ask for a seed phrase to “verify” exposure.

Was I affected?

Check for email from [email protected]. Trezor’s rule is simple: notification recipients are in the exposed set; no email means not affected per the company. The message should say whether exposure was full or partial. Save that original email. Compare later messages’ From domain, Reply-To, and links against it.

People searching “Trezor data breach,” “Trezor ShipMonk,” “81000 customers,” or “Trezor shipping provider incident” should land on the official trezor.io notice—not lookalike domains harvesting recovery phrases. Bookmark the real URL now.

What Trezor said—and what ShipMonk’s assurances cost

Trezor apologized, said investigation continues, and stressed that operations and devices were unaffected. It warned of fake emails, calls, and letters impersonating banks, exchanges, or Trezor itself. Never enter a wallet backup on a website. Never share it with “support.”

On privacy product work, Trezor continues to push options that reduce future address sharing: anonymous checkout email, crypto or disposable-card payment where practical, PO Boxes with the usual USPS identity caveats, and Anonymous Delivery—dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery. EU readiness was targeted around September 2026, with U.S. availability later in the year. Those features do not erase the current leak; they are for the next order.

ShipMonk, for its part, reportedly secured affected systems after the intrusion. SOC 2 paperwork did not prevent Metabase-path access or the retention miss. Other ShipMonk customers (Heatbit was among brands issuing related notices in August) should treat Trezor’s expansion as a cue to ask what their tenancy still held—not as automatic proof of identical scope.

Industry and campaign context

Third-party fulfillment remains the soft underbelly of hardware-wallet retail. Ledger’s Global-e and historical e-commerce incidents set the emotional template: order PII out, device crypto intact, phishing wave next. August 2026 also saw CEVA Logistics ripples into Valve/Steam hardware notices and Dutch retail brands. Trezor’s case is a different vendor (ShipMonk) and a reported Metabase path—not CEVA. Conflating the logistics waves muddies incident response.

The Metabase campaign itself spanned multiple verticals—form builders, laptop makers, fulfillment shops—wherever analytics instances sat on sensitive operational data. ShinyHunters-style extortion after access is a familiar second act. For crypto buyers, the sector lesson is blunt: cold storage protects keys; it does not anonymize the street address on the shipping label.

Prior Trezor third-party context still matters for phishing triage. A 2022 Mailchimp-adjacent wave and the 2024 support-portal exposure (~66k) already taught scammers that Trezor-adjacent PII converts. The ShipMonk dataset is larger and richer—especially once the 2019–2021 U.S. addresses reappeared.

Physical and social-engineering playbooks to expect

  • Courier SMS or email: “customs fee / failed delivery for your Trezor” with a payment or “reschedule” link
  • Letters on fake SatoshiLabs or Trezor letterhead asking you to “re-verify” a device after the ShipMonk breach
  • Voice calls that already know your name, phone, address, and order number—proof of data access, not legitimacy
  • Exchange or bank impersonation: “we see a suspicious Trezor withdrawal—confirm seed to unlock”
  • Doorstep or neighbor pretexting at full-exposure addresses
  • Recycled 2024 themes: “support portal remediation,” “migrate seed after breach,” fake merger or wallet-upgrade flows

None of those require cracking the Secure Element. Slow down. Hang up. Use bookmarks. If a caller already knows your order number and street address, that proves someone read a logistics file—not that they work for Trezor.

What you should do

  1. Search inbox and spam for mail from [email protected] about the ShipMonk incident; save the original.
  2. Treat any seed-phrase, “device sync,” or urgent wallet-migration request as a scam—especially messages that name-drop this breach.
  3. Do not click shipping, customs, or “reschedule delivery” links that cite your real address or order number out of the blue.
  4. Verify only via bookmarked trezor.io channels and the official support path—not via Reply-To addresses in unexpected mail.
  5. Brief household members and building/mailroom staff about courier and doorstep scams tied to a hardware-wallet order.
  6. If your full address was exposed, raise physical-security awareness for weeks after notification: package theft habits, unexpected visitors, and “inspection” pretexts.
  7. Rotate reused email passwords if the same mailbox guards exchange logins; turn on exchange withdrawal allowlists and delays so a panicked call cannot drain funds.
  8. Store seed backups offline; never photograph them “for support.” Moving coins to a new wallet only helps if you already shared a seed with a phisher.
  9. For future orders, prefer anonymous email, privacy-friendly payment where practical, PO Box or locker pickup, and Trezor’s Anonymous Delivery when available.
  10. Ignore secondary “was I affected” websites that ask for recovery phrases, wallet passwords, or live chat seed checks.
  11. Corporate or high-balance buyers: route future hardware through office receiving; document notification headers for insurance or incident files.
  12. Security teams at other ShipMonk customers: open a vendor ticket on Metabase exposure scope and purge evidence for aged order data.

Retention SLAs versus purge evidence

Trezor’s original August narrative leaned on a concrete operational control: delete or anonymize eShop purchase data after 90 days—the shortest window the company judged still covered delivery, returns, refunds, and replacements—and negotiate the same rule into fulfillment-partner terms. That is why the first disclosed set was not “every Trezor buyer since 2013.” Older customers were supposed to have aged out of ShipMonk’s logistics database before August 8.

The September expansion shows the control failed in practice for a large U.S. historical cohort. Written assurances that data had been deleted did not equal audited deletion. For product and privacy teams elsewhere, the lesson is operational: retention SLAs with 3PLs only help if partners actually purge on schedule, if analytics extracts (Metabase and similar) do not indefinitely retain query results, and if someone periodically checks purge evidence instead of accepting a confirmation email as gospel. A SOC 2 report does not replace that check.

Customers who ordered in 2019–2021 and assumed their shipping PII was long gone now face the same phishing and physical-security guidance as August’s recent buyers.

Comparing logistics breaches in summer 2026

The same season, CEVA Logistics’ European warehouse intrusion drove notices to Valve/Steam hardware buyers and multiple retail brands. Trezor’s ShipMonk/Metabase path is a different vendor and mechanism. What the incidents share is structural: physical goods force PII into 3PL systems, and those systems are now first-class breach targets. Hardware wallets simply raise the emotional and financial stakes of the phishing that follows.

Other crypto-hardware retail notices the same month underscore a crowded landscape. Readers should not merge every shipping leak into one incident—but scammers will mash brand names in lure copy anyway.

FAQ

Did hackers steal my Bitcoin through this? Not via this incident per Trezor—the leak is order PII at a shipper, not device keys.

Should I move coins to a new wallet? Only if you already shared a seed with a phisher. Otherwise focus on ignoring social engineering and hardening household phishing defenses.

Why did the count jump from ~14k to ~81k? ShipMonk still held ~67,000 U.S. order records from November 2019–August 2021 despite written deletion assurances Trezor says it repeatedly requested and received.

Is ShipMonk the same as CEVA? No. Different logistics provider and a reported Metabase analytics path.

What if I used a work address in 2020? Your employer mailroom may see scam packages or calls; brief receiving staff.

Does “no email” really mean safe? That is Trezor’s stated rule for this incident. Still stay alert to generic crypto phishing that does not need your exact address.

Timeline

Public reconstruction from Trezor and trade press runs roughly as follows. Around August 6, Metabase-related notification activity reaches ShipMonk in the customer-notice narrative BleepingComputer reported. ShipMonk investigates and on August 10 informs Trezor of unauthorized access. Trezor notifies the first cohort and publishes on August 13 (~13,689 customers; May 10–August 8, 2026 orders across seven countries). August 14 clarifies that partial-exposure rows may include older orders. On September 2, ShipMonk tells Trezor the breach also included 2019–2021 U.S. order data still retained despite deletion assurances. Trezor’s September 4 update puts ~67,000 additional U.S. customers in scope; combined impact ~81,000. BleepingComputer’s September 7 write-up ties the expansion to the Metabase campaign context and ShinyHunters extortion mail to ShipMonk.

That sequence matters for phishing triage. Scammers often move within hours of a public crypto-vendor disclosure—and again when a count expands. A [email protected] mail on notification day and an “urgent seed migration” mail the next morning are not the same class of message.

Canonical record and sources

Primary documents: Trezor’s shipping-provider incident blog (including the September 4 expansion) and BleepingComputer’s coverage of the ~81,000-customer impact, Metabase customer notices, and ShinyHunters extortion emails to ShipMonk. Secondary crypto outlets largely amplify those facts. Avoid forums claiming seed databases or wallet drains tied to this incident without evidence—Trezor’s position remains that devices and backups were untouched.

Trezor / ShipMonk 2026 on BreachHistory indexes the combined census at 80,689 after the September update.

Sources: Trezor official notice, BleepingComputer — impact reaches 81,000, BleepingComputer — August disclosure.