Trezor discloses data breach affecting nearly 14,000 customers

Trezor, a leading manufacturer of hardware cryptocurrency wallets, has disclosed a data breach that affects nearly 14,000 customers. The breach was caused by ShipMonk, Trezor’s shipping and logistics provider, being hacked by attackers who gained access to customer order data.

The compromised information includes full names, shipping addresses, email addresses, and phone numbers of customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The breach occurred between May 10th and August 8th, 2026, during which time ShipMonk was processing Trezor orders.

Trezor’s systems were not compromised in the breach, and its operations or services remain unaffected. However, customers who received orders during this period are at risk of targeted phishing attempts using the leaked information. Scammers can use the stolen data to send fake emails, make fake phone calls, or even impersonate banks, crypto exchanges, or Trezor itself.

The breach is linked to a vulnerability in Metabase, a third-party analytics platform used by ShipMonk. On August 6th, 2026, attackers exploited a critical SQL injection zero-day vulnerability to gain administrator access and carry out data theft attacks on customer instances. This vulnerability has since been patched by Metabase, but the incident highlights the importance of regular security updates and monitoring.

This is not Trezor’s first data breach in recent years. In January 2024, the company disclosed a breach that affected 66,000 users who had interacted with its support ticketing portal. Attackers used stolen information to launch phishing attacks on recipients, attempting to trick them into revealing their 24-word recovery seeds.

The Trezor breach serves as a reminder for customers to be vigilant about potential phishing attempts and to never share sensitive information via email or phone. With the increasing sophistication of cyber threats, it’s essential for individuals and organizations to prioritize security measures, including regular software updates, robust password management, and employee education on cybersecurity best practices.

As we navigate the complex landscape of online security, it’s crucial to stay informed about emerging threats and vulnerabilities. The Trezor breach highlights the importance of third-party risk assessment and mitigation in preventing data breaches. By staying proactive and vigilant, individuals can protect themselves from the devastating consequences of cyber attacks.


Source: Bleeping Computer — 2026-08-13