On August 10, 2026, ShipMonk — a shipping and fulfillment provider for Trezor — reported unauthorized access to systems holding customer order data. Trezor confirmed the incident on August 13. The breach exposed names, addresses, phone numbers, and email addresses for 13,689 customers. All affected orders were placed in the 90 days before August 8, 2026. The exposed data spanned 7 countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor stated that no crypto funds, wallets, or seed phrases were compromised. The company warned customers about potential phishing and social-engineering campaigns targeting the leaked contact information.
Trezor official blog, Insurance Journal