← Trezor

2026 Trezor — ShipMonk fulfillment breach; 13,689 customers (addresses/phones; Metabase path)

2026 13.7K records affected Share on X

Data compromised

13,689 customers total: 11,742 full (name, email, phone, shipping address) + 1,947 partial (name, city, email; may include some older orders pending ShipMonk verification). Order numbers. Devices/seeds/private keys not affected per Trezor. Markets: US, UK, Sweden, Colombia, Brazil, Italy, Portugal (orders ~May 10–Aug 8, 2026; 90-day retention).

Technical writeup

Verified third-party fulfillment breach — On August 10, 2026 ShipMonk informed Trezor of unauthorized access to systems holding customer order data; Trezor disclosed August 13 via blog and X. Approximately 13,689 customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal were notified: 11,742 with name/email/phone/shipping address and 1,947 with name/city/email (Trezor notes the partial set may include older orders pending verification). Primary order window May 10–August 8, 2026 under Trezor’s 90-day delete/anonymize policy with partners. BleepingComputer reported ShipMonk customer notices attributing access to a Metabase software vulnerability (Metabase notice ~August 6). Trezor states its own systems, devices, private keys, and wallet backups were not compromised; warns of elevated phishing by email/phone/post; plans Anonymous Delivery (EU ~September, US later 2026).

Root cause

Third-party breach at shipping/fulfillment partner ShipMonk; ShipMonk notices cite unauthorized access via a Metabase analytics software vulnerability (Metabase notified ShipMonk ~Aug 6). Trezor systems not compromised.

References