"A Shipping Partner Breach Just Exposed Thousands of Trezor Buyers"
Trezor has confirmed a data breach, but not one caused by anything Trezor itself did wrong. The exposure happened at ShipMonk, the third-party logistics company Trezor uses to pack and ship its hardware wallets. Around 13,689 buyers had their data exposed, with 11,742 of those customers facing full exposure: name, email address, phone number and shipping address, all in one place.
The affected orders were placed and fulfilled between 10 May and 8 August 2026, and the exposure spans seven countries, including the US, UK, Sweden, Colombia, Brazil, Italy and Portugal. If you bought a Trezor device in that window, there's a real chance your details were among those exposed, regardless of how carefully you've secured the wallet itself.
Why this matters more for crypto hardware buyers
A hardware wallet purchase is a strong signal about what someone owns. Anyone holding this leaked dataset now has a list of people who recently bought a device specifically designed to secure cryptocurrency, along with their name, phone number and home address. That is close to a ready-made target list for two very specific kinds of attack: SIM-swap attempts aimed at intercepting two-factor codes, and phishing emails or texts crafted to look like official Trezor support, urging the recipient to verify their device or wallet by entering a recovery phrase somewhere they absolutely should not.
This is the exact scenario hardware wallet vendors are supposed to protect against by design. Trezor's own security model assumes the device and its recovery phrase never touch the internet. But a breach one step removed, at a shipping partner rather than at Trezor itself, shows how a strong security model can still be undermined by a weak link elsewhere in the chain. Trezor didn't leak anything from its servers. Its shipping vendor did, and that was enough.
What to do if you ordered a Trezor between May and August 2026
Treat any email, text or call claiming to be from Trezor support as suspicious by default, especially anything referencing your recent order or asking you to enter a recovery phrase, PIN, or seed words anywhere outside the physical device itself. Trezor, like every legitimate hardware wallet vendor, will never ask for your recovery phrase under any circumstances. If you get a message that even implies otherwise, it's a scam.
Watch for SIM-swap warning signs in the weeks ahead: your phone suddenly losing signal without explanation, unexpected new-device activation messages, or being locked out of accounts that rely on SMS codes. If you use SMS-based two-factor authentication anywhere tied to financial accounts, this is a good moment to move to an authenticator app or a hardware security key instead, since SMS codes are exactly what a SIM-swap attack is designed to intercept.
More broadly, this breach is a reminder that your exposure isn't limited to the security of the companies you deal with directly. It extends to every vendor, shipping partner and support contractor in their supply chain. There's no consumer-side fix for that risk beyond staying alert to how it plays out: unexpected contact referencing a real purchase, timed to look legitimate.