13,689
Trezor, a leading manufacturer of cryptocurrency hardware wallets, has announced a data breach affecting approximately 13,689 of its customers. This incident was not a compromise of Trezor's own systems or its hardware wallets. Instead, it was a supply chain attack targeting Trezor's third-party shipping and logistics provider, ShipMonk. Attackers breached ShipMonk's database, exfiltrating the personal contact and order information of customers who had received shipments between May and August 2026. While no cryptocurrency or wallet recovery seeds were compromised, the leaked Personally Identifiable Information (PII) places affected customers at a heightened risk of sophisticated and targeted phishing and physical threats.
On August 10, 2026, ShipMonk notified Trezor of a security breach. An unauthorized party had gained access to a database containing order information for Trezor customers. The breach exposed the following data for customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10, 2026, and August 8, 2026:
The incident affects 11,742 customers with full data exposure and another 1,947 with partial exposure. The primary threat stemming from this breach is not the direct loss of funds, but the potential for highly convincing follow-on attacks. Threat actors can use the leaked data to craft targeted phishing emails, SMS messages (smishing), or even phone calls, impersonating Trezor, a bank, or another trusted entity. Their goal would be to trick users into revealing their wallet's 24-word recovery seed, which would grant the attacker full control over the user's crypto assets.
This incident is a classic example of a supply chain attack targeting a weaker link in a company's operational ecosystem.
The direct impact is the exposure of PII for nearly 14,000 individuals. The indirect, but more severe, impact is the significantly increased risk of financial loss for these individuals through future social engineering attacks. Knowing a person's name, address, and that they own a Trezor wallet allows criminals to craft highly personalized and believable scams. This could include emails about a fake security incident requiring them to 'verify' their recovery seed on a malicious website, or even physical threats and home invasions (so-called "$5 wrench attacks"). This incident erodes trust in the security of the broader ecosystem, even when the core product remains secure.
No specific IOCs related to the breach at ShipMonk were provided.
This was a third-party breach, so internal hunting is not applicable. However, Trezor customers should be vigilant for:
trezor-support.com, trezor-verify.ioFor affected customers, the focus is on personal vigilance:
trezor.io domain.For companies like Trezor, response includes:
Educating customers about the risks of phishing and the importance of never sharing their recovery seed is the primary defense against follow-on attacks.
Implement a robust vendor risk management program to vet and continuously monitor the security practices of all third-party partners.
Start of the period during which customer data was exposed.
End of the period during which customer data was exposed.
ShipMonk informs Trezor of the security breach.
Trezor publicly discloses the data breach and begins notifying customers.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.