https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident
ShipMonk, one of Trezor’s shipping providers, has experienced a data breach that exposed sensitive customer order data, including full names, shipping addresses, phone numbers, and email addresses. Trezor devices are secure, but affected customers could experience an increase in phishing attempts. This data breach can potentially affect new customers who received an order from the following countries: US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between 10th of May and 8th of August 2026. If you are unsure whether you were affected, please check your email inbox for a message from help@trezor.io
On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data. This occurred due to a data breach. Investigation is ongoing.
We’re extremely sorry to inform our community that customer personal information, including full names, phone numbers, email addresses, and shipping addresses, has been accessed by an unauthorized actor during this breach.
The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email). The breach is limited due to Trezor’s strict 90-day data storage policy (we were also able to negotiate the same terms with fulfillment partners, who follow the same policy).
