What Happened in the Trezor Data Breach?
Trezor, the company behind a popular line of hardware cryptocurrency wallets, has told customers that their personal information was exposed in a breach tied to a shipping partner. The issue did not start inside Trezor’s own network. Instead, it began at ShipMonk, the logistics company Trezor uses to fulfill and ship customer orders.
According to Trezor, ShipMonk informed the company of unauthorized access to its systems in August 2026. The attackers reportedly took advantage of a security flaw in Metabase, a third-party analytics platform that ShipMonk relied on for data reporting. Because of this flaw, an outside party was able to reach customer order records stored within that system.
Trezor has been clear that this incident did not touch its own infrastructure. The company stated that its systems were not compromised and that Trezor devices themselves remain secure. However, the order data held by its shipping vendor was still reachable by the attacker, which is how customer details ended up exposed.
Once Trezor learned of the incident, it moved to investigate the scope of the exposure and notify affected customers. The breach was publicly disclosed in August 2026, matching the timeline of when Trezor first learned about the ShipMonk compromise. This type of third-party vendor breach has become increasingly common, since companies often share sensitive customer data with logistics and analytics partners to keep operations running smoothly.
Who was affected?
The Trezor data breach affects customers who placed orders during a specific window. Trezor said the incident affects people who received orders between May 10 and August 8, 2026. As a result, anyone who ordered a Trezor hardware wallet or accessory during that period could be impacted.
Trezor has disclosed a specific affected count, which sets this incident apart from many breaches where numbers remain unclear. The company reported that 11,742 customers experienced full data exposure, while another 1,947 customers had partial data exposed. Together, this puts the total number of affected individuals at nearly 14,000.
Geographically, the breach reaches beyond the United States. Trezor identified affected customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. This means the incident has a genuine international footprint, though customers based in the US are still directly affected and covered by US consumer protection considerations.
It is worth noting that this breach involves customer order records rather than employee data or health information. Because Trezor sells hardware wallets used to store cryptocurrency, its customer base may include individuals who value privacy and security highly. This makes the exposure of personal contact details especially concerning for many of those affected.
What Information Was Potentially Exposed?
The data exposed in this breach centers on order and contact information rather than financial account numbers or passwords. Still, the categories involved are sensitive enough to enable targeted scams. Trezor separated the exposure into two tiers based on how much data was accessed for each customer.
- Full name
- Email address
- Phone number
- Shipping address
- City (for the partial exposure group)
For the larger group of nearly 11,742 customers, the exposure included full name, email, phone number, and shipping address together. This combination is particularly useful to scammers because it lets them craft convincing, personalized messages. Meanwhile, the smaller group of 1,947 customers saw a narrower exposure limited to name, city, and email.
Because this breach did not expose passwords, recovery seeds, or financial account details, the risk of direct account takeover appears lower than in some other incidents. However, the exposed contact information still creates a real risk of phishing and impersonation. Scammers could use these details to pose as Trezor support, a bank, or a cryptocurrency exchange in an attempt to trick victims into revealing sensitive wallet information.
This risk is heightened by the nature of Trezor’s customer base. Since these customers are known to own cryptocurrency hardware wallets, attackers may see them as high-value targets. As a result, affected individuals should expect a higher chance of targeted phishing attempts referencing their real order details, which can make scam messages appear more legitimate than usual.
What is the company doing?
After learning of the breach from ShipMonk, Trezor moved to investigate the incident and communicate with affected customers. The company published a public blog post explaining what happened and which data categories were involved. In addition, Trezor reached out directly to affected individuals to make sure they understood the scope of the exposure.
Trezor has also emphasized that its own systems and devices remain unaffected and secure. This distinction matters because it tells customers that their cryptocurrency holdings were not directly threatened by this particular incident. Still, the company has warned customers to stay alert, since exposed contact details can fuel convincing phishing attempts.
Separately, ShipMonk stated that it worked with outside technical experts to investigate the incident after being notified by Metabase. According to ShipMonk, Metabase patched the vulnerability that was exploited and invalidated all active sessions tied to the flaw. This response was intended to prevent further unauthorized access through the same weakness.
What Should Affected Individuals Do?
Watch for Phishing and Impersonation Attempts
Because names, emails, phone numbers, and shipping addresses were exposed, affected customers should expect an increase in phishing attempts. Scammers may pose as Trezor, a bank, or a cryptocurrency exchange to appear trustworthy. They could reach out by email, phone call, or even physical mail using the leaked address details.
To stay protected, avoid clicking links in unexpected messages, even if they reference a real order or address. Instead, go directly to the official Trezor website or app to verify any account-related communication. Remember that Trezor will never ask for your 24-word recovery seed, so any message requesting it should be treated as a scam.
Monitor Your Credit Reports
Even though financial account numbers were not part of this exposure, monitoring your credit report is still a smart precaution. Exposed names and contact details can sometimes be combined with other leaked data from unrelated breaches to attempt identity theft. Checking your credit report regularly helps you catch suspicious activity early.
You can request free credit reports from the three major credit bureaus once per year. In addition, many banks and credit card issuers now offer free credit monitoring tools. Reviewing these reports every few months makes it easier to spot unfamiliar accounts or inquiries before they cause serious damage.
Be Cautious With Unsolicited Calls and Texts
Since phone numbers were exposed for thousands of customers, affected individuals may receive unexpected calls or text messages. These could involve fake customer support representatives or urgent-sounding security alerts. Scammers often create a sense of urgency to pressure victims into acting quickly without thinking.
If you receive a call claiming to be from Trezor or a related service, hang up and contact the company directly using its official website. Never provide personal information, recovery phrases, or verification codes over the phone. This simple habit can prevent most social engineering attempts tied to this type of breach.
Consider Consulting a Data Breach Attorney
Given that thousands of customers had their personal information exposed through a third-party vendor, some affected individuals may want to understand their legal options. A data breach attorney can review the specific facts of your exposure and explain whether you may be eligible for compensation. This is particularly relevant if you experience direct harm, such as fraud attempts tied to the leaked data.
Many attorneys who handle these cases offer free initial consultations. As a result, there is little downside to asking questions about your situation. This step can help you understand your rights while the broader investigation into the ShipMonk and Metabase incident continues.
