Trezor reported a data leak of almost fourteen thousand customers

8/16/2026, 07:00 AMЕвгения Слив

On August 13, Trezor, a manufacturer of hardware crypto wallets, officially announced the leak of personal data of thirteen thousand six hundred eighty-nine users. The reason for the incident was the hacking of the systems of its logistics partner ShipMonk. The contractor's team notified Trezor of the unauthorized access on August tenth. The attackers obtained information about orders placed between May tenth and August eighth. According to preliminary data, customers from the United States, Great Britain, Sweden, Colombia, Brazil, Italy and Portugal were affected. Eleven thousand seven hundred and forty-two customers had their personal information stolen from them, which they left on the logistics company's website. Another nineteen hundred and forty-seven people were partially affected, as only their names, cities, and email addresses appeared in the stolen database.

Representatives of Trezor stressed that this is the first time since the company was founded in 2000, when a leak revealed the phone numbers and delivery addresses of customers. The developers also warned about a possible increase in the number of phishing attacks and sent special alerts to all affected users. The scale of the incident was significantly limited due to the strict data retention policy. The manufacturer of hardware wallets requires logistics partners to delete or depersonalize the ordered information ninety days after delivery. That is why information about earlier purchases in ShipMonk systems was already missing and did not fall into the hands of intruders.

ShipMonk said it has already strengthened the protection of hacked systems, and Trezor continues its own investigation into the circumstances of the incident. At the same time, the manufacturer announced a new Anonymous Delivery service that will allow you to pick up devices from special lockers and receive parcels in regular neutral packaging. This service ensures that the shipping data will not be stored in the company's systems. It is planned to be launched in the European Union by September, and in the United States by the end of 2017. Earlier in August, the manufacturers of Trezor and Foundation hardware wallets had already warned users about a wave of phishing attacks against the background of the incident with Coldcard devices. The industry continues to strengthen security measures to protect customers' personal data and digital assets.

Popular news