Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping provider and logistics partner, got hacked.

During the incident, the attackers gained access to customers' order data, including their full names, shipping addresses, email addresses, and phone numbers.

As the company explained in a Thursday blog post, the resulting data breach affects customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026.

"On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data," Trezor said. "The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email)."

The company added that its operations or services were not impacted due to the breach, that its systems were not compromised, and noted that all Trezor devices are secure.

It also warned affected customers to be suspicious of any messages asking them for personal information, as they may experience an increase in phishing attempts.

"To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts," it noted. "Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor."

A Trezor spokesperson was not immediately available for comment when contacted by BleepingComputer today for more information regarding the incident.

Trezor disclosed another data breach in January 2024 after threat actors gained access to its third-party support ticketing portal.

The hardware cryptocurrency wallet vendor revealed at the time that 66,000 users who have interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed during the incident.

After the breach, Trezor confirmed that the attackers used the stolen information in phishing attacks attempting to trick the recipients into giving away the 24-word recovery seeds they were given when setting up their Trezor wallets.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report