Skip to content
Trezor Says ShipMonk Breach Exposed Order Data for 13689 Customers

Trezor Says ShipMonk Breach Exposed Order Data for 13689 Customers

Newscord • August 14, 2026

Data breach at ShipMonk exposed personal data for 13,689 Trezor customers. Exposed data included full names, shipping addresses, email addresses, and phone numbers.

Whether the article mentions the breach’s underlying cause (Metabase zero-day SQLi)

Beat 2 · The divide, quote v quote

“ attackers exploited a vulnerability in the third-party analytics platform Metabase ”

“ its third-party fulfillment partner, ShipMonk, had experienced “unauthorized access” ”

Do not take our word for it. Here is what they published.

Record Rainfall Kills Eight in Japan’s Chiba, Strands Thousands at Narita Airport

15 sources compared →

NTSB Says Bird Strike Preceded Ryanair 737-800 Engine Failure Near Thessaloniki

25 sources compared →

Hardware wallet maker Trezor disclosed that a breach at its fulfillment partner ShipMonk exposed order data for 13,689 customers, with the company saying the incident affected customers who received orders 90 days prior to August 8.

Trezor said 11,742 customers had their names, emails, phone numbers, and shipping addresses leaked, while another 1,947 customers had just their names, cities and emails exposed.

In a Thursday post, Trezor said, " On Monday , August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data," and it added that its operations or services were not impacted.

BleepingComputer reported that the breach affected customers from the United States, the United Kingdom , Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026.

Trezor also warned that affected customers " could experience an increase in phishing attempts " even though it said its systems and devices remain secure.

Trezor told customers to treat unexpected with suspicion and warned that scammers can use leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor.

In its disclosure, Trezor emphasized, "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts," and it said it is continuing to investigate the incident.

BleepingComputer reported that ShipMonk told customers the attackers exploited a vulnerability in the third-party analytics platform Metabase, and that Metabase had patched the vulnerability and invalidated all active sessions.

The breach comes after other Trezor-related incidents, including a January 2024 disclosure that 66,000 users who interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed.

Bitcoin Magazine also pointed to a broader pattern, noting that in 2020 an unauthorized party accessed Ledger’s e-commerce and marketing database, leaking over 1 million email addresses and the personal data of nearly 10,000 customers.

Trezor said the scope was limited by a policy requiring partners to delete or anonymize order data 90 days after delivery, which it said meant older orders were no longer held in ShipMonk’s systems.

“ delete or anonymize order data 90 days after delivery ”

Decrypt reported that Trezor attributed the limited scope to a policy requiring partners to delete or anonymize order data 90 days after delivery, and it said customers who did not receive a notification email are not affected.

Trezor also announced an Anonymous Delivery option, with ForkLog saying it would allow customers to pick up devices from lockers, receive packages in plain packaging, and ensure delivery data is not retained.

ForkLog added that the service is expected to launch in the EU by September and in the US by the end of the year, while Trezor continued to investigate the breach.

CoinDesk reported that Trezor told it it has no confirmed cases of the exposed data being published, shared, or offered for sale yet, and that it is unaware of any scam or hack attempt linked to the incident so far.

Story read · 21 outlets · 3 disagreements · 1 fact unevenly covered

Apple Proposes 15% App Store Fees for External US Purchases in Epic Games Case

how 14 outlets framed it →

Drought Exposes Nero’s Bridge in Rome’s Tiber Near St. Peter’s Basilica

11 sources compared →

Hurricane Warning Issued for Hawaii’s Big Island as Tropical Storm Lala Approaches

49 sources compared →

Whether the article mentions the breach’s underlying cause (Metabase zero-day SQLi)

“ attackers exploited a vulnerability in the third-party analytics platform Metabase ”

“ its third-party fulfillment partner, ShipMonk, had experienced “unauthorized access” ”

Some outlets add root-cause detail; others stop at partner compromise.

Western Alternative ( 14 )

Western Mainstream ( 1 )

Every outlet we compared, the headline it ran, and a link to the original article.

Trezor warns 14,000 customers after fulfilment partner suffers data breach

Trezor shipping partner breach exposes data of 13,689 customers

Trezor Data Breach Exposes 13,689 Customer Addresses

Data Breach At Trezor Leaks Info On Nearly 14,000 Bitcoin Wallet Users

A third-party security breach exposes the shipping addresses of 14,000 Trezor buyers.

Trezor reports data from 14K users exposed through shipping provider

Trezor discloses data breach affecting 13,689 customers

Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers

Trezor Customer Data Exposed in Shipping Partner Breach

Trezor Breach Exposes 13,700 Customers' Personal Data

Trezor Reports Data Breach Affecting Nearly 14,000 Customers

Trezor says 13,689 customers hit by data breach at shipping partner

Trezor reports data from 14K users exposed through shipping provider

"Trezor" warns 13,689 customers of an advanced phishing wave after shipping partner breach

Trezor Warns of Phishing Risk After 13,689 Customers' Data Exposed: What Happened?

Trezor discloses data breach affecting nearly 14,000 customers

Trezor: Customer Data Exposed in Shipping Breach

Breaking: Trezor says ShipMonk breach exposed data of 13,689 customers

Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers

Trezor Says Shipping Breach Exposed 13,689 Customers

Trezor Issues Urgent Data Breach Warning, Says Wallets Remain Secure

Get every Technology and Science story like this one, in one email

Daily or weekly, only the topics you follow, each with the difference our analysis found across the outlets covering it.

Apple Proposes 15% App Store Fees for External US Purchases in Epic Games Case

Drought Exposes Nero’s Bridge in Rome’s Tiber Near St. Peter’s Basilica

Hurricane Warning Issued for Hawaii’s Big Island as Tropical Storm Lala Approaches

Record Rainfall Kills Eight in Japan’s Chiba, Strands Thousands at Narita Airport