Trezor data breach: ShipMonk (a logistics provider handling Trezor deliveries) disclosed unauthorized access to its systems containing customer order data. The breach affected 13,689 customers so far, with full exposure (names, addresses, phone numbers, emails) for 11,742 individuals, and partial exposure (names, cities, emails) for 1,947 others. This marks the first time since Trezor’s founding in 2013 that customer phone numbers and shipping addresses have been exposed in a security incident.
How did the Trezor data breach happen and why?
According to what the team shared, the breach occurred because ShipMonk’s systems were the ones hacked, and definitely not Trezor’s own internal infrastructure. Thankfully, Trezor has a strict 90-day data retention policy in place, which actually helped save the day by keeping the impact limited.
Now, because of that policy, older order data had already been deleted or anonymized, preventing exposure of a much larger dataset.
Since the company makes it a requirement for all of its fulfillment partners to stick to those exact same cleanup rules, it helped make sure that only the most recent orders were actually at risk.
What are the risks for affected users
While Trezor devices and private keys remain secure, exposed personal data could enable sophisticated phishing attacks. Scammers may use leaked information to craft convincing emails, phone calls, or even physical letters impersonating Trezor, exchanges, or banks, just like we see them all the time.
Similar incidents have led to victims losing significant funds. Just look at the Ledger user who lost a staggering $1.07 million after falling for a fake support letter that asked for their recovery phrase. It’s a huge reminder to never, ever share your wallet backup or type it in anywhere online, even if the message looks totally legit.
Trezor’s response and preventive measures
Trezor has notified all affected customers via email (from help@trezor.io) and is working with ShipMonk to investigate the breach further. ShipMonk has since secured its systems and strengthened security.
At the same time, to prevent future incidents, Trezor plans to launch an Anonymous Delivery option (featuring locker pickup, neutral packaging, and automatic deletion of shipping identifiers) in the European Union (EU) by September 2026 and in the U.S. by year-end.




