Trezor says a breach at shipping provider ShipMonk exposed personal order data for 13,689 customers. The larger group had names, email addresses, phone numbers, and shipping addresses exposed. Trezor says its own systems and wallet devices were not compromised, so this is not evidence that recovery seeds or private keys were stolen.
The practical risk is targeted phishing. A scammer who knows that someone bought a hardware wallet—and knows the person’s name, address, phone number, and email—can make a fake support call, delivery notice, security alert, or mailed letter look unusually convincing.
Who is affected by the Trezor data breach
Trezor published the incident on August 13, 2026, after ShipMonk reported unauthorized access on August 10. The main affected window covers customers who received a Trezor order between May 10 and August 8, 2026, in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal.
There is one important exception. Trezor says the 1,947 customers in the partial-exposure group may include older orders, and it is still verifying that timeframe with ShipMonk. Trezor says it emailed every affected customer. To check safely, open the official incident page from Trezor’s website yourself instead of following a link in an unexpected message.
| Group | Data Trezor says was exposed | What it does not establish |
|---|---|---|
| 11,742 customers | Name, email, phone number, and shipping address | No evidence in Trezor’s notice that the wallet device, backup, or private keys were accessed |
| 1,947 customers | Name, city, and email address | The exact order-age window is still being verified |
| All other Trezor users | Trezor says it did not send them an affected-customer notice | An unrelated phishing message can still impersonate Trezor |
What to do if your order data was exposed
- Do not rotate the wallet backup only because of this notice. Contact details alone do not let someone open the wallet. A rushed “migration” offered by email, phone, direct message, or a website is more likely to be the attack.
- Never type the wallet backup into a website. Trezor’s guidance says never to share it or enter it online. A caller who knows your real address or order details still has no legitimate reason to request the words.
- Verify messages outside the message. Type
trezor.iointo the browser, use the official support path, and compare any claimed incident or update with the company’s own blog. Do not trust the displayed sender name. - Harden the exposed contact channels. Use a unique email password and phishing-resistant MFA where available. Add a carrier account PIN or port-out lock because phone-number exposure can support SIM-swap attempts.
- Treat physical mail and calls as possible phishing. Do not confirm wallet ownership, holdings, device model, or recovery setup. A legitimate courier problem does not require a recovery seed, PIN, or wallet connection.
- Review personal safety. Shipping-address exposure is more sensitive than an email-only leak. Avoid discussing holdings publicly, secure delivery and home-access routines, and report specific threats or extortion attempts to local law enforcement.
If a message contains a suspicious link, inspect it without signing in or connecting a wallet. Gridinsoft’s online scanner can help check a URL or downloaded file, but a clean result does not make a request for a wallet backup legitimate. Our guide to crypto-wallet validation scams shows why “verify,” “synchronize,” and “secure your assets” prompts are common seed-theft lures.
If you already clicked, called, or entered the backup
- Clicked but entered nothing: close the page, do not download its software, and check the browser’s download list. If a file ran, disconnect it from sensitive accounts and scan the device.
- Shared an account password: change it from a known-clean device, sign out other sessions, and replace reused passwords. Protect the email account first because it can reset other accounts.
- Shared the wallet backup: treat the wallet as compromised. Using a known-clean device and official Trezor instructions, create a new wallet backup on the hardware device and move assets to addresses controlled by that new backup. Do not reuse the exposed words.
- Approved an unknown transaction: record transaction IDs and destination addresses, revoke risky token approvals where applicable, and contact the relevant exchange or law-enforcement channel promptly. Blockchain transfers generally cannot be canceled.
A real-looking message is not proof of authenticity when the attacker already has order data. Previous wallet-themed phishing has used urgent firmware updates, account-verification claims, fake support agents, and recovery forms. The safest test remains simple: no legitimate support process needs the complete wallet backup on a webpage or over a call.
False assumptions to avoid
- “Trezor wallets were hacked.” Trezor attributes the breach to ShipMonk and says its systems, products, and devices remain secure.
- “The message knows my address, so it must be real.” The leaked address is exactly what can make a fraudulent message persuasive.
- “I need to install emergency firmware from the email.” Open Trezor Suite or the official site independently. Never install an update from an unsolicited attachment or lookalike domain.
- “I received no notice, so every Trezor message is safe.” Unrelated mass phishing can still use the brand. Verify the domain and the requested action every time.
References
- Trezor Team, Trezor, “Recent customer data exposed in shipping provider incident”, August 13, 2026. Accessed August 14, 2026.
- Trezor, “Scams and phishing”. Accessed August 14, 2026.

