A Shipping Vendor's Breach Grows Six-Fold
Cryptocurrency hardware wallet maker Trezor has disclosed that a data breach at its third-party shipping and logistics provider, ShipMonk, now affects 81,000 customers — a sharp jump from the 14,000 customers reported when the incident was first disclosed on August 13, 2026.
Trezor says attackers exploited a critical SQL injection zero-day in ShipMonk's Metabase analytics platform to gain access to shipping records.
Timeline
| Date | Event |
|---|---|
| May 10 – August 8, 2026 | Breach window during which international customer data was exposed |
| August 13, 2026 | Trezor discloses the initial breach — ~14,000 customers |
| September 7, 2026 | Trezor announces expanded impact after learning ShipMonk retained additional historical records |
Who's Affected
| Group | Count | Detail |
|---|---|---|
| International customers | ~14,000 | Brazil, Colombia, Italy, Portugal, Sweden, UK |
| US customers | ~67,000 | Orders placed between November 2019 and August 2021 |
| Total | ~81,000 |
The expansion happened because ShipMonk had retained older order records well beyond what Trezor initially believed was exposed — a reminder that breach scope assessments at third-party vendors can shift significantly as investigations progress.
What Was Exposed
- Full names
- Shipping addresses
- Email addresses
- Phone numbers
- Order numbers
Trezor emphasizes that no wallet seed phrases, private keys, or device firmware were involved — the breach was confined to shipping and order metadata held by ShipMonk, not Trezor's own infrastructure or the security of the hardware devices themselves.
Why This Matters for Crypto Holders Specifically
Unlike a typical e-commerce data leak, a breach exposing "this person owns a hardware crypto wallet, and here is their home address" carries elevated risk. Trezor's own advisory flags this directly:
"Be aware of the increased risk of phishing. The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks."
Physical risk is not hypothetical in this space — hardware wallet owners have previously been targeted for in-person robbery ("wrench attacks") after their identities and holdings were inferred from leaked purchase data.
Recommendations for Affected Customers
- Assume your name, address, and phone number are exposed if you ordered a Trezor device in the affected windows, and treat unsolicited contact accordingly.
- Never enter your recovery seed anywhere — Trezor will never ask for it, and this breach does not change that guidance, but attackers will use the leaked data to make phishing attempts more convincing.
- Be skeptical of "replacement device" or "security update" outreach referencing your order number — verify independently via Trezor's official site before acting.
- Consider your physical security posture if your holdings and address may now be linkable by a motivated attacker.
- Watch for spear-phishing that references specific order details, since that level of personalization is now possible with the leaked data.