← Trezor

2026 Trezor — ShipMonk fulfillment breach; ~80.7k customers after Sep update (+~67k legacy US)

2026 80.7K records affected Share on X

Data compromised

~80,689 customers total after Sep 2026 update: initial ~13,689 (US/UK/Sweden/Colombia/Brazil/Italy/Portugal orders ~May 10–Aug 8 2026) plus ~67,000 additional US customers who ordered Nov 2019–Aug 2021 whose data ShipMonk had not deleted despite deletion assurances. Name, email, phone, shipping address, order number. Devices/seeds/private keys not affected per Trezor.

Technical writeup

Verified Trezor notices and BleepingComputer — August–September 2026. ShipMonk informed Trezor August 10 of unauthorized access; Trezor disclosed ~13,689 customers August 13. September update: another ~67,000 U.S. customers (orders Nov 2019–Aug 2021) exposed after ShipMonk retained data despite repeated written deletion assurances. Combined impact ~81,000 / catalog 80,689. Metabase vulnerability path cited in customer emails; ShinyHunters extortion emails to ShipMonk reported by BC. Trezor systems/devices not compromised. Physical-security and phishing risk emphasized. recordsAffected 80689; companyConfirmed true. Update September 2026: Help Net Security and Trezor’s own warnings note the leaked ShipMonk contact data (names, emails, phones, shipping addresses) is already being abused for phishing emails, fraudulent calls, and letters — heightened physical-security risk for hardware-wallet owners. This is abuse of fulfillment-contact data from the ShipMonk Metabase path, not a separate confirmed compromise of Trezor’s own mail infrastructure. Devices/seeds remain unaffected per Trezor.

Root cause

Third-party breach at shipping/fulfillment partner ShipMonk; ShipMonk notices cite unauthorized access via a Metabase analytics software vulnerability (Metabase notified ShipMonk ~Aug 6). Trezor systems not compromised.

References