Topic overview
Briefly
- Trezor confirmed a data breach at its logistics partner ShipMonk, affecting over 13,000 customers.
- The exposed data includes names, email addresses, phone numbers, and shipping addresses from orders placed between May 10 and August 8, 2026.
- Trezor is developing an Anonymous Delivery option to enhance customer privacy and prevent future breaches.
What happened
In a significant data breach, Trezor, a cryptocurrency hardware wallet manufacturer, revealed that personal information of more than 13,000 customers was compromised due to a security incident at its logistics partner, ShipMonk. The breach specifically affected customers who placed orders between May 10 and August 8, 2026, across several countries including the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The exposed data included names, email addresses, phone numbers, and shipping addresses, raising concerns about potential phishing attacks targeting affected individuals.
Trezor's investigation indicated that the breach was limited to orders placed in certain countries within the last 90 days. The company is currently verifying the details and timeframe of the breach with ShipMonk, which is responsible for storing and shipping Trezor products. ShipMonk is required to adhere to Trezor's 90-day data retention policy, which mandates the deletion or anonymization of customer data after this period. However, the breach has raised alarms about the security of customer information, as Trezor has never before experienced a breach that exposed such sensitive data.
In response to the incident, Trezor has warned customers to be vigilant against phishing attempts, as the exposed information could be used by criminals to impersonate banks, crypto exchanges, or Trezor itself. The company has advised customers to never share their wallet backup information online or with anyone. This breach has prompted Trezor to prioritize the development of an "Anonymous Delivery" option, which aims to allow customers to complete purchases without linking their real-world identity or home address to their orders. This service is expected to launch in the European Union in September 2026 and in the United States by the end of the year.
The breach has not only affected Trezor's reputation but has also opened discussions about the security measures that logistics partners must implement to protect customer data. As the cryptocurrency market continues to grow, the importance of safeguarding personal information becomes increasingly critical. Trezor's commitment to enhancing customer privacy through the upcoming Anonymous Delivery service reflects the company's recognition of the need for improved security measures in the face of evolving threats in the digital landscape.

Comprehensive report
Full story,
in detail.
Trace the developments that led here, see how the story evolved, and understand the forces and wider context surrounding it.
