What Trezor reported and when
Trezor, the hardware wallet manufacturer, disclosed on Thursday via a company blog post that a compromise at its logistics partner ShipMonk led to a customer data exposure. According to Trezor, ShipMonk notified the company on August 10, 2026. The affected orders were those received between May 10 and August 8, 2026. Trezor emphasized that its own systems were not compromised and that "your Trezor device is secure." A company spokesperson was not immediately available for further comment when contacted by BleepingComputer.
Exact data exposed and the customers affected
Trezor quantified the impact: "The incident affects 11,742 customers with full exposure (name, email, phone number, shipping address) and 1,947 customers with partial exposure (name, city, email)." The company named the countries where affected recipients received shipments: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The exposed records, Trezor said, came from order data stored by the shipping provider.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildPhishing, impersonation, and Trezor’s warning
Trezor warned affected customers to be suspicious of outgoing communications and said they should expect an increase in targeting. "Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor," the company wrote. The post made clear that while the hardware devices themselves remained secure and Trezor's systems were not breached, the leaked contact and shipping details materially raise the risk of more sophisticated social-engineering campaigns against those customers.
Related logistics breaches: Valve, CEVA Logistics, and Trezor’s prior incident
The disclosure arrives in a broader pattern of supply-chain and logistics provider breaches. The same report that covered Trezor noted that Valve had informed Steam hardware customers in Europe that hackers stole their data after a compromise at CEVA Logistics, Valve’s shipping partner. Trezor itself has a prior incident on record: in January 2024 the vendor disclosed a data breach after threat actors accessed its third-party support ticketing portal. At that time Trezor said some 66,000 users who had interacted with Trezor Support since December 2021 may have had names, usernames, and email addresses exposed; attackers subsequently used that information in phishing attacks attempting to trick recipients into revealing the 24-word recovery seeds used to set up Trezor wallets.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: The incident reinforces a point called out in a related assessment: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The Blue Report 2026 — cited in the same source — measures defenses across 338 million simulated techniques, underscoring how compromises at a partner can defeat controls that are otherwise effective.
- Procurement and operations leaders responsible for logistics: Organizations that rely on third-party shippers should expect scrutiny of vendors’ access controls and incident notification practices, since the exposure here originated in a partner’s systems rather than the vendor’s own infrastructure.
- End users and customers: Individuals named in Trezor’s tally should be on heightened alert for tailored phishing by email, phone, or even postal fraud. Trezor’s explicit list of plausible impersonation targets includes banks, crypto exchanges, and the vendor itself.
Closing observation
Trezor’s post draws a sharp line between the technical security of devices and the operational security of supply-chain partners. The vendor’s claim that "your Trezor device is secure" addresses one set of risks, but the published counts — 11,742 with full exposure and 1,947 with partial exposure — highlight a separate, human-facing threat: attackers armed with names, addresses, phones, and emails. For the nearly 14,000 affected customers named in Trezor’s disclosure, the immediate question is not whether their hardware has been altered, but whether the leaked contact data will be used to deceive them. The incident also joins other logistics-provider compromises, making clear that third-party access paths remain a primary vector for large-scale personal data exposure.
Source: BleepingComputer — Trezor discloses data breach affecting nearly 14,000 customers



