ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers

ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 (TL-2026-2007) is a medium-severity data breach, first published 2026-08-13. It has no confirmed attribution, affects ShipMonk Third-party order fulfillment / warehouse and logistics, maps to 12 MITRE ATT&CK techniques (T1199, T1213, T1566), and is covered by 9 detection rules and 5 indicators of compromise.

Key facts for TL-2026-2007

Threat ID
TL-2026-2007
Severity
MEDIUM
Status
ACTIVE
Category
DATA_BREACH
First published
2026-08-13
Last reviewed
2026-08-13
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
cryptocurrency, financial services, e-commerce and fulfillment logistics, hardware wallet consumer electronics
Target regions
united states of america, united kingdom, sweden, colombia, brazil, italy, portugal
Detection rules
9
Indicators of compromise
5

Trezor's third-party logistics provider ShipMonk suffered unauthorized access to systems holding customer order data, exposing full contact and shipping details for 11,742 customers and partial data (name, city, email) for 1,947 more across seven countries. Trezor's own devices, firmware, and infrastructure were not compromised, but the exposed PII creates elevated phishing, vishing, and impersonation risk against a population of confirmed hardware-wallet owners.

How ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 works

On August 10, 2026 (a Monday), ShipMonk — a third-party order fulfillment and logistics provider that stores and ships Trezor hardware wallets — notified Trezor that an unauthorized party had accessed systems containing customer order data. Trezor publicly disclosed the incident on August 13, 2026, stating that no device, private key, wallet backup, or Trezor-owned infrastructure was affected; the compromise was confined to ShipMonk's fulfillment systems.

The exposure affects 13,689 customers who placed orders shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal between May 10 and August 8, 2026 (the affected order window). Of these, 11,742 customers had full names, email addresses, phone numbers, and shipping addresses exposed, along with order numbers; 1,947 customers had a reduced data set of name, city, and email address exposed. Trezor attributes the relatively bounded scope to a 90-day data-retention policy with its fulfillment partners, which meant older order records had already been deleted or anonymized before the intrusion.

No attack vector, initial-access method, or attacker identity has been disclosed by either ShipMonk or Trezor. This is consistent with a third-party/vendor trust-relationship compromise (MITRE ATT&CK T1199) rather than a direct compromise of Trezor's own environment: the adversary gained access to sensitive customer records by reaching a trusted downstream processor rather than Trezor's core platform.

The practical risk from this breach is not asset theft (no device or seed material was exposed) but downstream social engineering: the leaked name/email/phone/address/order-number combination is exactly the material needed to make phishing emails, spoofed support calls, and fraudulent physical mail convincingly reference a victim's real, recent Trezor purchase. Trezor explicitly warned customers to expect "sophisticated phishing attempts" using the leaked information, including spoofed calls and impersonation of support or financial platforms.

This is not Trezor's first third-party data exposure. On January 17, 2024, an unrelated breach of Trezor's third-party support-ticketing portal exposed names/usernames and email addresses (and potentially phone numbers/addresses) of roughly 66,000 customers who had contacted support since December 2021; Trezor later confirmed 41 documented cases of attackers using that leaked data to send fraudulent "firmware validation" emails soliciting victims' 24-word recovery seed phrases, though no funds were reported stolen. The industry precedent is starker still: Ledger's June 2020 breach (via a misconfigured e-commerce API key) resulted in a December 2020 public dump of 272,000 customer records containing full names, postal addresses, and phone numbers, which directly fueled a wave of 2021 physical-mail scams — tampered "replacement" hardware wallets shipped to victims' real addresses with instructions to enter recovery seeds into a device designed to exfiltrate them. The ShipMonk breach reproduces the exact same data profile (name + address + order context) against the same class of victim (confirmed hardware-wallet owners), making that physical/vishing threat model directly applicable here even though no such attack has yet been reported against this specific dataset.

As a stated mitigation, Trezor announced it will roll out an "Anonymous Delivery" option — neutral packaging, locker pickup, and automatic post-delivery deletion of shipping data — to the EU by September 2026 and the US by the end of 2026.

MITRE ATT&CK techniques used in TL-2026-2007

Initial Access

T1199 Trusted Relationship; T1566 Phishing; T1566.004 Spearphishing Voice

Collection

T1213 Data from Information Repositories

Resource Development

T1585 Establish Accounts; T1585.002 Email Accounts

Reconnaissance

T1589 Gather Victim Identity Information; T1589.002 Email Addresses; T1598 Phishing for Information; T1598.004 Spearphishing Voice

Impact

T1657 Financial Theft

Defense Evasion

T1684.001 Impersonation

Affected products and versions in ShipMonk Fulfillment Partner Breach Exposes Data of 13,689

  • ShipMonk — Third-party order fulfillment / warehouse and logistics platform
    Vulnerable versions: Customer order records for orders shipped May 10 - August 8, 2026
  • Trezor (SatoshiLabs) — Customer order and shipping data processed via the ShipMonk fulfillment integration
    Vulnerable versions: 11,742 records: full name, email address, phone number, shipping address, order number; 1,947 records: name, city, email address

Remediation for ShipMonk Fulfillment Partner Breach Exposes Data of 13,689

Immediate actions

  • Treat any unexpected contact referencing a recent Trezor order (phone calls, emails, texts, or physical mail) as a probable social-engineering attempt, and verify only through official channels (https://trezor.io, help@trezor.io)
  • Never enter a 24-word recovery seed phrase into any website, app, device prompt, support chat, or in response to a 'firmware validation' request — Trezor and legitimate hardware-wallet vendors never ask for it
  • Affected customers (orders shipped to US/UK/Sweden/Colombia/Brazil/Italy/Portugal between May 10 and August 8, 2026) should assume their name, email, phone number, and/or shipping address is exposed and apply heightened scrutiny to any inbound contact referencing their order

Longer-term hardening

  • Enforce strict data-minimization and retention limits on third-party fulfillment/logistics vendors handling customer PII (Trezor's existing 90-day retention policy is explicitly credited with limiting this breach's scope)
  • Adopt privacy-preserving delivery options (e.g. Trezor's planned 'Anonymous Delivery': neutral packaging, locker pickup, automatic post-delivery deletion) to reduce the PII footprint held by fulfillment vendors
  • Contractually require third-party vendors with access to customer PII to undergo periodic security assessments and to provide prompt breach notification

Weaknesses (CWE) in ShipMonk Fulfillment Partner Breach Exposes Data of 13,689

CWE-200

Timeline of ShipMonk Fulfillment Partner Breach Exposes Data of 13,689

  • Unrelated industry precedent: competitor hardware-wallet vendor Ledger is breached via a misconfigured e-commerce API key, exposing roughly 1 million customer emails.
  • Ledger's fuller dataset of 272,000 records (names, postal addresses, phone numbers) is publicly dumped on a hacking forum, later fueling 2021 physical-mail scams that shipped tampered 'replacement' devices to leaked addresses.
  • Unrelated prior incident: Trezor's third-party support-ticketing portal is breached, exposing names/emails of ~66,000 customers who had contacted support since December 2021; 41 later-confirmed cases involved fraudulent seed-phrase phishing using the leaked data.
  • Start of the order window later confirmed as affected: customer orders shipped from this date onward through August 8, 2026 fall within the exposed dataset.
  • End of the affected order window; order records from May 10 through this date remained within ShipMonk's 90-day retention period at the time of the intrusion.
  • ShipMonk secures and hardens the affected systems following discovery of the unauthorized access.
  • ShipMonk notifies Trezor that an unauthorized party accessed systems containing customer order data.
  • Trezor publicly discloses the breach, directly notifying the 13,689 affected customers and warning of elevated phishing, vishing, and impersonation risk using the leaked data.
  • Planned EU rollout of Trezor's 'Anonymous Delivery' option (neutral packaging, locker pickup, automatic post-delivery deletion), announced as a mitigation in response to this breach.
  • Planned end-of-year US rollout of 'Anonymous Delivery,' completing the mitigation Trezor announced following this incident.

Sources cited for ShipMonk Fulfillment Partner Breach Exposes Data of 13,689

Threats related to ShipMonk Fulfillment Partner Breach Exposes Data of 13,689

Detection coverage for TL-2026-2007

As of 2026-08-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2007 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats