ShipMonk, a shipping and fulfillment provider used by retailers like Trezor, suffered a data breach in August 2026 exposing customer names, addresses, phone numbers, and emails for orders shipped between May and August 2026 across several countries. Affected individuals should watch for phishing attempts referencing recent orders and avoid clicking suspicious shipment links.
| Company | ShipMonk |
|---|---|
| Industry | Retail |
| Data Types Exposed | Full Names, Shipping Addresses, Phone Numbers, Email Addresses |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unauthorized Network Access |
| Regulators Notified | Not Publicly Disclosed |
What Happened in the ShipMonk Data Breach?
ShipMonk, a company that handles order fulfillment and shipping logistics for retailers, experienced a data breach that exposed sensitive customer order information. The exposed details reportedly include full names, shipping addresses, phone numbers, and email addresses. This incident came to light because one of ShipMonk’s retail clients, hardware wallet maker Trezor, publicly disclosed that its customer data had been affected.
According to the notice, unauthorized access to ShipMonk’s systems occurred in August 2026. As a result, order data tied to customers who received shipments during a specific window became exposed. Because ShipMonk functions as a third-party logistics provider, the breach did not stem from Trezor’s own systems. Instead, it originated further down the supply chain, inside a partner that many online retailers rely on to move packages.
Details about the exact method the attackers used to gain access have not been publicly disclosed. However, this incident fits a familiar pattern where a single vendor breach ripples outward to affect the customers of many separate businesses. Investigators are still working to determine the full scope of the intrusion. In response, ShipMonk has been coordinating with affected client companies, including Trezor, to notify impacted individuals.
Who was affected?
The ShipMonk data breach affects customers of retailers that use ShipMonk for order fulfillment and shipping. In this case, Trezor confirmed that new customers who placed orders shipped from specific countries during a defined period were impacted. Those countries include the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
The affected window spans orders shipped between May 10 and August 8, 2026. Because ShipMonk works with many e-commerce brands beyond Trezor, other retailers’ customers could potentially be affected as well. The total number of individuals impacted across all of ShipMonk’s clients has not been publicly disclosed.
It’s also worth noting that this breach centers on order and shipping data rather than account credentials or payment card numbers. Even so, the exposure spans multiple countries, meaning both US residents and international customers are involved. Anyone who placed an order fulfilled by ShipMonk during the affected period should consider themselves potentially at risk.
What Information Was Potentially Exposed?
The ShipMonk data breach exposed a specific set of order-related personal details. This information, while not including financial account numbers, is still sensitive enough to enable targeted scams and identity-related fraud.
- Full names
- Shipping addresses
- Phone numbers
- Email addresses
Even without Social Security numbers or payment details, this combination of data carries real risk. For example, scammers often use names paired with home addresses and phone numbers to craft convincing phishing messages. Because the victims are known to have purchased from a specific retailer, criminals can tailor scam messages to reference that exact brand, making the fraud attempt far more believable.
In addition, exposed phone numbers and emails open the door to targeted smishing and vishing (voice phishing) campaigns. Attackers frequently impersonate delivery services or the retailer itself, asking victims to click a link or confirm a shipment. This is especially concerning given that a known shipping and order history was exposed alongside contact details, giving criminals a ready-made pretext for their outreach.
What is the company doing?
Following discovery of the breach, ShipMonk began investigating the incident and worked to notify the retail clients whose customer data was involved. As part of that process, Trezor issued a public notice to inform its own affected customers about what happened and what data was involved.
Because the incident touches multiple retail brands and countries, ShipMonk’s response has included ongoing coordination with those business clients as more details emerge. Affected retailers, in turn, have been urging their customers to stay alert for suspicious messages. At this time, no specific credit monitoring or identity protection service tied to this breach has been publicly named.
What Should Affected Individuals Do?
Watch for Phishing and Scam Attempts
Because names, addresses, phone numbers, and emails were exposed, affected individuals should be especially cautious about unexpected messages referencing recent orders. Scammers may pose as ShipMonk, a retailer, or a delivery carrier to trick victims into clicking malicious links or sharing further information.
Therefore, avoid clicking links in unsolicited texts or emails about a shipment, even if they reference real order details. Instead, go directly to the retailer’s official website or app to check order status. If a message asks for payment information or login credentials, treat it as a red flag.
Monitor Your Accounts and Credit Reports
Even though financial data wasn’t part of this exposure, it’s still wise to check your credit reports regularly for unfamiliar activity. This habit helps catch identity theft early, whether or not it’s connected to this specific breach.
You can request free credit reports from each of the three major bureaus once a year. As a result, spacing out your requests throughout the year gives you ongoing visibility into your credit file. If you notice unfamiliar accounts or inquiries, report them immediately.
Be Alert to Targeted Social Engineering
Because attackers now have your name paired with your address and contact details, they can craft highly personalized scam attempts. This might include fake customer service calls claiming there’s an issue with a recent delivery.
To protect yourself, never share verification codes, passwords, or payment details over the phone with someone who contacted you first. Legitimate companies rarely ask for sensitive information this way. When in doubt, hang up and call the company back using a verified number.
Update Passwords and Enable Extra Security
Although login credentials don’t appear to be part of this exposure, it’s still a good time to strengthen your account security. This is especially true for any accounts tied to the email address that was exposed.
Consider enabling two-factor authentication wherever it’s offered, particularly for email and financial accounts. In addition, use unique passwords for each account so that a breach at one company doesn’t put your other accounts at risk.
