ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers — Threadlinqs Intelligence
As of 2026-08-13, ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers is a medium-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 5 indicators of compromise.
Threat ID: TL-2026-2007 · Severity: MEDIUM · Status: ACTIVE · Category: DATA_BREACH
Trezor's third-party logistics provider ShipMonk suffered unauthorized access to systems holding customer order data, exposing full contact and shipping details for 11,742 customers and partial data
On August 10, 2026 (a Monday), ShipMonk — a third-party order fulfillment and logistics provider that stores and ships Trezor hardware wallets — notified Trezor that an unauthorized party had accessed systems containing customer order data. Trezor publicly disclosed the incident on August 13, 2026, stating that no device, private key, wallet backup, or Trezor-owned infrastructure was affected; the compromise was confined to ShipMonk's fulfillment systems.
The exposure affects 13,689 customers who placed orders shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal between May 10 and August 8, 2026 (the affected order window). Of these, 11,742 customers had full names, email addresses, phone numbers, and shipping addresses exposed, along with order numbers; 1,947 customers had a reduced data set of name, city, and email address exposed. Trezor attributes the relatively bounded scope to a 90-day data-retention policy with its fulfillment partners, which meant older order records had already been deleted or anonymized before the intrusion.
No attack vector, initial-access method, or attacker identity has been disclosed by either ShipMonk or Trezor. This is consistent with a third-party/vendor trust-relationship compromise (MITRE ATT&CK T1199) rather than a direct compromise of Trezor's own environment: the adversary gained access to sensitive customer records by reaching a trusted downstream processor rather than Trezor's core platform.
The practical risk from this breach is not asset theft (no device or seed material was exposed) but downstream social engineering: the leaked name/email/phone/address/order-number combination is exactly the material needed to make phishing emails, spoofed support calls, and fraudulent physical mail convincingly reference a victim's real, recent Trezor purchase. Trezor explicitly warned customers to expect "sophisticated phishing attempts" using the leaked information, including spoofed calls and impersonation of support or financial platforms.
This is not Trezor's first third-party data exposure. On January 17, 2024, an unrelated breach of Trezor's third-party support-ticketing portal exposed names/usernames and email addresses (and potentially phone numbers/addresses) of roughly 66,000 customers who had contacted support since December 2021; Trezor later confirmed 41 documented cases of attackers using that leaked data to send fraudulent "firmware validation" emails soliciting victims' 24-word recovery seed phrases, though no funds were reported stolen. The industry precedent is starker still: Ledger's June 2020 breach (via a misconfigured e-commerce API key) resulted in a December 2020 public dump of 272,000 customer records containing full names, postal addresses, and phone numbers, which directly fueled a wave of 2021 physical-mail scams — tampered "replacement" hardware wallets shipped to victims' real addresses with instructions to enter recovery seeds into a device designed to exfiltrate them. The ShipMonk breach reproduces the exact same data profile (name + address + order context) against the same class of victim (confirmed hardware-wallet owners), making that physical/vishing threat model directly applicable here even though no such attack has yet been reported against this specific dataset.
As a stated mitigation, Trezor announced it will roll out an "Anonymous Delivery" option — neutral packaging, locker pickup, and automatic post-delivery deletion of shipping data — to the EU by September 2026 and the US by the end of 2026.
Target sectors: cryptocurrency, financial services, e-commerce and fulfillment logistics, hardware wallet consumer electronics
Target regions: united states of america, united kingdom, sweden, colombia, brazil, italy, portugal
Timeline
- Unrelated industry precedent: competitor hardware-wallet vendor Ledger is breached via a misconfigured e-commerce API key, exposing roughly 1 million customer emails.
- Ledger's fuller dataset of 272,000 records (names, postal addresses, phone numbers) is publicly dumped on a hacking forum, later fueling 2021 physical-mail scams that shipped tampered 'replacement' devices to leaked addresses.
- Unrelated prior incident: Trezor's third-party support-ticketing portal is breached, exposing names/emails of ~66,000 customers who had contacted support since December 2021; 41 later-confirmed cases involved fraudulent seed-phrase phishing using the leaked data.
- Start of the order window later confirmed as affected: customer orders shipped from this date onward through August 8, 2026 fall within the exposed dataset.
- End of the affected order window; order records from May 10 through this date remained within ShipMonk's 90-day retention period at the time of the intrusion.
- ShipMonk notifies Trezor that an unauthorized party accessed systems containing customer order data.
- ShipMonk secures and hardens the affected systems following discovery of the unauthorized access.
- Trezor publicly discloses the breach, directly notifying the 13,689 affected customers and warning of elevated phishing, vishing, and impersonation risk using the leaked data.
- Planned EU rollout of Trezor's 'Anonymous Delivery' option (neutral packaging, locker pickup, automatic post-delivery deletion), announced as a mitigation in response to this breach.
- Planned end-of-year US rollout of 'Anonymous Delivery,' completing the mitigation Trezor announced following this incident.
Related threats
- Pokémon Center Confirms Customer Data Breach via CEVA Logistics Supply-Chain Compromise
- SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII, Fuels Phishing Campaign
- Callback Phishing Campaign Impersonates Robinhood With Fake Sign-In Alerts (LevelBlue SpiderLabs)
- Malwarebytes Subscription Renewal Scam — Fake-Invoice / Refund-Bait Callback Phishing Campaign ("Account Maintenance Update")
- Microsoft Teams Phishing: Attackers Impersonate IT Helpdesk for Initial Access
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTC
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 5 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, MEDIUM, threat intelligence, cybersecurity, T1199, T1566, T1566.004, T1213, T1589, T1589.002, T1598, T1598.004, T1585, T1585.002