2026 Trezor — ShipMonk fulfillment breach; ~80.7k customers after Sep update (+~67k legacy US)
Data compromised
~80,689 customers total after Sep 2026 update: initial ~13,689 (US/UK/Sweden/Colombia/Brazil/Italy/Portugal orders ~May 10–Aug 8 2026) plus ~67,000 additional US customers who ordered Nov 2019–Aug 2021 whose data ShipMonk had not deleted despite deletion assurances. Name, email, phone, shipping address, order number. Devices/seeds/private keys not affected per Trezor.
Technical writeup
Verified Trezor notices and BleepingComputer — August–September 2026. ShipMonk informed Trezor August 10 of unauthorized access; Trezor disclosed ~13,689 customers August 13. September update: another ~67,000 U.S. customers (orders Nov 2019–Aug 2021) exposed after ShipMonk retained data despite repeated written deletion assurances. Combined impact ~81,000 / catalog 80,689. Metabase vulnerability path cited in customer emails; ShinyHunters extortion emails to ShipMonk reported by BC. Trezor systems/devices not compromised. Physical-security and phishing risk emphasized. recordsAffected 80689; companyConfirmed true. Update September 2026: Help Net Security and Trezor’s own warnings note the leaked ShipMonk contact data (names, emails, phones, shipping addresses) is already being abused for phishing emails, fraudulent calls, and letters — heightened physical-security risk for hardware-wallet owners. This is abuse of fulfillment-contact data from the ShipMonk Metabase path, not a separate confirmed compromise of Trezor’s own mail infrastructure. Devices/seeds remain unaffected per Trezor.
Root cause
Third-party breach at shipping/fulfillment partner ShipMonk; ShipMonk notices cite unauthorized access via a Metabase analytics software vulnerability (Metabase notified ShipMonk ~Aug 6). Trezor systems not compromised.
References
- https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident
- https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/
- https://cryptopotato.com/trezor-provider-shipmonk-breach-exposed-order-data-for-13689-hardware-wallet-customers/
- https://bitcoinmagazine.com/news/trezor-data-breach-leaks-customer-info
- https://x.com/Trezor/status/2087885428313543059
- https://cryptoslate.com/with-violent-crypto-home-invasions-surging-a-data-breach-exposing-over-10000-trezor-owners-puts-physical-safety-on-the-line/
- https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/
- https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/
- https://www.helpnetsecurity.com/2026/09/08/trezor-shipping-partner-breach-phishing-attacks/
- https://trezor.io/learn/security-privacy/personal-security-standards/scams-and-phishing