Mastodon Mastodon Mastodon Mastodon

Customer data leak at Trezor via ShipMonk raises phishing risks

Photo of author

CyberSecureFox Editorial Team

Published:

Hardware crypto wallet manufacturer Trezor has confirmed a data breach affecting almost 14,000 customers. The incident did not occur in Trezor’s own infrastructure but at its logistics partner ShipMonk, which handles device shipping. Fully exposed were the full names, email addresses, phone numbers and shipping addresses of 11,742 buyers; for another 1,947 people, their names, email addresses and city of residence were leaked. Customers from seven countries were affected — the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal — who received orders between 10 May and 8 August 2026. Trezor warns of a high likelihood of phishing attacks using the stolen data.

Timeline and scope of the incident

According to Trezor’s official statement, attackers gained access to order data through ShipMonk’s systems. The company divided affected customers into two groups based on the extent of information exposure:

  • 11,742 customers — full compromise: names, email addresses, phone numbers and physical shipping addresses;
  • 1,947 customers — partial compromise: names, email addresses and city information.

The compromise window covers orders delivered from 10 May to 8 August 2026. Trezor stresses that the company’s own infrastructure was not attacked, all services are operating normally, and the hardware wallets remain secure — users’ cryptographic keys and seed phrases were not affected.

Likely attack vector

Trezor is not disclosing technical details of the ShipMonk compromise. However, according to BleepingComputer, affected ShipMonk customers received notifications stating that the incident was caused by a vulnerability in the third-party analytics platform Metabase. Reportedly, on 6 August Metabase representatives informed ShipMonk that unknown attackers had exploited a vulnerability to access customer data. After discovery, Metabase is believed to have fixed the vulnerability and invalidated all active sessions, while ShipMonk engaged external information security specialists to investigate.

It should be noted that linking the incident to a specific Metabase vulnerability is based on secondary sources and is not confirmed in Trezor’s official statement. A CVE identifier for the alleged vulnerability has not been published in the available materials.

Phishing risk

The main threat to those affected is targeted phishing. Trezor directly warns customers:

“Fraudsters may use the compromised information to send fake emails and messages, make phone calls, and may impersonate representatives of banks, cryptocurrency exchanges or even Trezor itself.”

The leaked data set — name, email address, phone number and physical address — creates ideal conditions for convincing social engineering attacks. Attackers can craft highly personalized messages referencing the real fact of a Trezor device purchase, which significantly increases the chances of phishing success. For hardware wallet owners, the ultimate goal of such attacks is obvious — obtaining the seed phrase that grants full control over their funds.

A recurring issue: attacks via third parties

This is already the second Trezor customer data breach in the past two years that has occurred through a third-party provider. In January 2024, attackers gained access to a third-party technical support portal used by the company. That time, data on 66,000 users who had contacted support since December 2021 were compromised — names, usernames and email addresses. Trezor later confirmed that the stolen information was used in phishing campaigns aimed at stealing seed phrases.

The pattern is clear: while Trezor’s own infrastructure is highly protected, the weak link remains its supply chain of vendors. A similar situation is seen in other industries — compromises of logistics and service partners are becoming a systemic problem.

Recommendations for affected customers

Trezor customers who made purchases between May and August 2026 should take specific protective measures:

  • Do not trust incoming communications — any emails, SMS messages or phone calls allegedly from Trezor, banks or crypto exchanges that ask for your seed phrase, password or to follow a link should be considered fraudulent. Trezor never asks for a seed phrase;
  • Verify the sender — if you receive suspicious messages, contact Trezor only through the official website, not via links in received emails;
  • Strengthen account protection — enable two-factor authentication on all related accounts, especially on cryptocurrency exchanges and email services;
  • Monitor for suspicious activity — watch for unusual login attempts to your accounts and unexpected password reset requests;
  • Do not disclose that you own cryptocurrency — the leak of physical addresses combined with confirmed ownership of a hardware wallet creates a risk of not only digital but also physical threats.

The Trezor–ShipMonk incident once again demonstrates that the security of a product is determined not only by the protection measures of its manufacturer, but by the entire supply chain. For hardware wallet users, the key rule remains unchanged: a seed phrase must never be shared with anyone — not by email, not by phone, not through a web form, regardless of how convincing the request may appear.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.