Trezor’s Third-Party Shipping Provider Hit by Data Breach, Exposing Customer Information
A data breach at ShipMonk, a shipping provider used by Trezor, has compromised the personal information of nearly 14,000 customers. The incident is not related to Trezor’s own systems or devices, but rather the third-party company that handles order delivery for the hardware cryptocurrency wallet manufacturer.
The affected customers, located in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal, placed orders between May 10 and August 8. Hackers gained access to customer names, addresses, email addresses, and phone numbers through a vulnerability in Metabase, which was exploited by the notorious extortion group ShinyHunters.
Trezor has taken swift action, notifying all impacted customers via email and advising them to be cautious of suspicious communication that requests personal information or prompts for immediate action. The company’s own systems were not compromised, and its devices remain secure. However, the affected customers may be targeted by more sophisticated phishing attempts.
The breach is limited due to Trezor’s strict 90-day data storage policy, which means that customer data is typically deleted after three months. However, for the 1,947 customers with partial exposure, older orders might have been accessed as well. ShipMonk has not publicly acknowledged the incident, and it remains unclear how many companies or individuals may be affected.
This incident highlights the risks associated with third-party vendors and the importance of implementing robust security measures to protect customer data. It also underscores the need for companies to regularly review their vendor relationships and ensure that they are meeting the same level of security standards as the manufacturer.
In this case, Trezor’s quick response and transparency demonstrate its commitment to protecting its customers’ information. The incident serves as a reminder to all users to remain vigilant about their online security and to be cautious of any suspicious communication or requests for personal information.
Practically speaking, users should review their email communications from ShipMonk and other vendors, look out for any unusual activity or requests, and consider implementing additional security measures such as two-factor authentication to protect themselves against potential phishing attempts.
Source: SecurityWeek — 2026-08-14