TLDR
- Trezor’s fulfillment partner ShipMonk suffered unauthorized access, exposing data of nearly 14,000 customers
- Compromised data includes names, email addresses, phone numbers, and shipping addresses
- Trezor’s own systems and hardware wallets were not affected
- Affected customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal are at risk of phishing attacks
- This is the first breach in Trezor’s 13-year history to expose customer phone numbers and shipping addresses
Crypto hardware wallet maker Trezor has warned nearly 14,000 customers that their personal data was exposed after its shipping partner, ShipMonk, suffered a data breach.
We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days…
— Trezor (@Trezor) August 13, 2026
The incident was confirmed on August 13, 2026. Trezor said the data of 11,742 customers, including names, email addresses, phone numbers, and shipping addresses, was compromised. Another 1,947 customers had their names, cities, and email addresses exposed.
Who Was Affected
Customers who received Trezor products between May 10 and August 8 across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal are potentially at risk. Customers who purchased through Amazon were not affected, as those orders are handled by a separate fulfillment partner.
Trezor said it has notified all affected customers by email. Anyone who did not receive a notification was not impacted.
Trezor was clear that its own systems were not breached. “Your Trezor device is secure,” the company said. The risk to customers is indirect, primarily through phishing attempts.
Scammers could use the leaked information to impersonate Trezor, banks, or crypto exchanges via fake emails, phone calls, or letters in the mail. Customers should be cautious of any unexpected contact claiming to be from Trezor.
A Growing Threat to Crypto Holders
Data breaches are rising globally. According to cybersecurity firm SentinelOne, breaches have increased 17% in 2026 compared to 2025, with roughly 2,090 attacks occurring worldwide each week.
Once stolen data is sold online, criminals reuse it for years. Extortionists have been known to use home addresses to demand ransoms between $700 and $1,000, and some have mailed fake hardware devices to victims.
Physical attacks on crypto holders are also rising. In-person coercion attacks totalled $124 million in the first half of 2026, according to blockchain security firm Certik.
Trezor said this is the first time in its 13-year history that customer phone numbers and shipping addresses have been exposed in a breach. Previous incidents in 2024 and 2022 affected support portal users and email addresses, but not physical shipping data.
Trezor’s internal firmware and on-device security have never been remotely breached to steal funds.
Hardware wallet rival Ledger suffered a similar third-party data breach in January 2026, tied to its e-commerce partner. In 2020, a Ledger breach affected nearly 300,000 users, and scammers later mailed fake devices to victims of that incident.
Trezor has confirmed no stolen data has been published, sold, or used in a scam attempt linked to this breach so far.
Stop guessing and start investing with confidence. KnockoutStocks gives you the AI insights, market intelligence, and stock research you need to spot opportunities, cut through the noise, and make smarter investment decisions — all in one powerful platform.
Sign up today and get 50% OFF full access to our premium stock picks.
Simply use coupon code SPECIAL50 at checkout to claim your exclusive discount.







