Incident case file
Sign in to watchTrezor/ShipMonk — Customer Data Breach (13,689 Clients Exposed)
7 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
10 beatsAugust 13, 2026 — Trezor, the hardware wallet manufacturer, publicly disclosed that ShipMonk — one of its e-commerce fulfillment partners — had suffered a data breach exposing the personal information of 13,689 Trezor customers.
Root cause: A critical SQL injection zero-day vulnerability in Metabase, the business intelligence and analytics tool used by ShipMonk for order management, was exploited by an attacker to gain unauthorized access to ShipMonk's customer order database.
August 6, 2026: Metabase zero-day exploited. Attacker gains access to ShipMonk's order management systems. ShinyHunters extortion group sends emails to ShipMonk demanding payment in exchange for not publishing the stolen data.
August 10, 2026: ShipMonk notifies Trezor of the data breach. Data exposed: order information for customers who purchased Trezor products between May 10 and August 8, 2026 (90-day retention window).
August 13, 2026: Trezor publishes official disclosure: 'We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data.' Trezor sends email notifications to all 13,689 affected customers. Customers who purchased via Amazon are confirmed unaffected. Trezor states no evidence of misuse, sharing, or sale of the data at the time of disclosure.
Data exposed — Full data (11,742 customers): name, email address, phone number, shipping address. Partial data (1,947 customers): name, city, email address. Countries affected: US, UK, Sweden, Colombia, Brazil, Italy, Portugal.
Trezor hardware wallets and seed phrases are NOT compromised. The breach is entirely external to Trezor's systems and devices.
Primary risk for affected customers: targeted phishing (attackers now know who owns a Trezor and their contact information), impersonation (fake Trezor support), and physical 'wrench attacks' (home address exposure for known hardware wallet owners).
Trezor confirms: developing an 'Anonymous Delivery' feature to reduce personal data required for future orders. No compensation announced. No evidence of misuse confirmed as of August 20, 2026. ShinyHunters not formally confirmed as responsible party.
Precedent: Ledger/Global-e breach (January 2026) exposed 292,000 customers via Shopify — same pattern of manufacturer-secure, fulfillment-partner-breached attack.
Sources and coverage
- Articletrezor.iohttps://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident
- Articlebleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/
- Articlecoindesk.comhttps://www.coindesk.com/tech/2026/08/13/trezor-warns-14-000-users-after-fulfilment-partner-suffers-data-breach
- Articlenews.bloomberglaw.comhttps://news.bloomberglaw.com/ip-law/crypto-firm-trezor-says-data-breach-exposed-thousands-of-clients
- Articleinvesting.comhttps://www.investing.com/news/cryptocurrency-news/trezor-reports-data-breach-affecting-nearly-14000-customers-93CH-4858836
- Articlebitcoinmagazine.comhttps://bitcoinmagazine.com/news/trezor-data-breach-leaks-customer-info
- Articlebitbo.iohttps://bitbo.io/news/trezor-shipmonk-data-breach/
- Articletechjournal.orghttps://techjournal.org/trezor-shipmonk-data-breach
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)