
A breach at fulfillment partner ShipMonk exposed order-linked personal data for about 14,000 Trezor customers in seven countries, prompting phishing warnings while Trezor said its own systems and hardware wallets were not compromised.
Trezor said a data breach at fulfillment partner ShipMonk exposed customer information tied to orders received between May 10 and Aug. 8, 2026 in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. The company said 13,689 customers were affected in total, or about 14,000: 11,742 had names, email addresses, phone numbers and shipping addresses exposed, while another 1,947 had names, cities and email addresses compromised, with order numbers also included. Trezor said its own systems and devices remain secure, warned affected users about elevated phishing risk, and said no stolen data had surfaced for sale so far.