Skip to content
ShipMonk Breach Puts Nearly 14K Trezor Customers at Phishing Risk

ShipMonk Breach Puts Nearly 14K Trezor Customers at Phishing Risk

Coinmarketcap • August 14, 2026

Trezor disclosed on Aug. 13 that an unauthorized party accessed customer order data held by ShipMonk, the company's third-party fulfillment provider. The breach affected people who ordered Trezor products between May 10 and Aug. 8, 2026, with deliveries going to the US, the UK, Sweden, Colombia, Brazil, Italy, and Portugal. ShipMonk reportedly notified Trezor of the incident on Aug 10.

Trezor requires fulfillment partners to delete or anonymize customer order data within 90 days of delivery. That policy meant records for older shipments had already been cleared when the breach occurred, containing the exposure to orders placed within the three months. Customers who did not receive a direct notification email from Trezor were not affected.

The company called it the first incident in its 13-year history to expose customer phone numbers and shipping addresses. In response, it is accelerating the rollout of an Anonymous Delivery option. That service will route packages through parcel lockers, use neutral packaging, strip sender details, and automatically delete shipping identifiers after delivery. The EU launch is targeted for September 2026, with the US following by the end of the year.

Physical attacks on crypto holders have been accelerating in 2026. Security firm CertiK verified 52 such incidents in the first half of the year, up from 39 over the same period in 2025. invasions have overtaken kidnapping as the most common method. Chainalysis put the total amount stolen through violence at more than $30 million during that period, putting the year on course to surpass the $58 million stolen across all of 2025.

One case reported on Aug. 13 involved a French couple targeted in three invasions in less than a month. They had moved into a previously owned by crypto millionaires whose tax records and address had leaked onto the dark web. The incident underlines how data from breaches at any point in a supply chain can surface in criminal networks long after the initial exposure.

Extracted Entities

Attack Types (1)

Companies (2)