
{"id":212814,"date":"2026-08-13T16:47:18","date_gmt":"2026-08-13T16:47:18","guid":{"rendered":"https:\/\/mycryptomania.com\/?p=212814"},"modified":"2026-08-13T16:47:18","modified_gmt":"2026-08-13T16:47:18","slug":"trezor-provider-shipmonk-breach-exposed-order-data-for-13689-hardware-wallet-customers","status":"publish","type":"post","link":"https:\/\/mycryptomania.com\/?p=212814","title":{"rendered":"Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers"},"content":{"rendered":"<p>The breach hit 11,742 customers whose names, email addresses, phone numbers, and shipping addresses were all exposed, plus 1,947 whose names, cities, and email addresses were taken.<\/p>\n<p>Order numbers were included. Trezor said the records came from orders received between May 10 and August 8, 2026, and named the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal as the affected markets.<\/p>\n<p>\u201cOur systems were not compromised, and your Trezor device is secure,\u201d the company stated, adding that hardware wallets, private keys, and wallet backups were not affected.<\/p>\n<p>A 90-day data storage policy, which Trezor said it negotiated into its fulfillment partners\u2019 terms as well, kept older orders out of the exposed set, but every affected customer was contacted individually by email.<\/p>\n<h2>Phishing Warning Follows Address Leak<\/h2>\n<p>Trezor told customers to treat any communication that demands immediate action or requests personal information as \u201csuspicious,\u201d to check claims against official channels, and to never enter a wallet backup on a website or share it with anyone.<\/p>\n<p>Its disclosure said affected customers \u201ccould experience an increase in phishing attempts.\u201d But it seems users found that statement cynical. \u201cPhishing?? They have physical addresses, you imbeciles,\u201d wrote an X user posting as Chikun, in a reply that collected about 159 likes within the hour. Another reply called the exposure \u201cirl phishing.\u201d<\/p>\n<p>We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data. This affects new customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received an order within the 90 days\u2026<\/p>\n<p>\u2014 Trezor (@Trezor) <a href=\"https:\/\/x.com\/Trezor\/status\/2087885428313543059?ref_src=twsrc%5Etfw\">August 13, 2026<\/a><\/p>\n\n<p>The phishing risk still tracks what followed a comparable incident at a rival. <em>CryptoPotato<\/em> reported that scammers used order data leaked from Ledger\u2019s e-commerce partner Global-e to send phishing emails <a href=\"https:\/\/cryptopotato.com\/ledger-users-targeted-in-phishing-scam-following-global-e-data-breach\/\">claiming<\/a> Ledger and Trezor had merged, pushing recipients to enter 24-word recovery phrases on a fake site.<\/p>\n<h2>Yet Another Trezor Incident<\/h2>\n<p>Trezor said it is investigating and will publish updates on its blog. The company also mentioned building an Anonymous Delivery option, with neutral packaging, generic sender details, and automatic deletion of shipping identifiers.<\/p>\n<p>Not an easy time for being a Trezor customer, as they have been reached through vendors twice before. Attackers sent phishing emails through a Trezor mailing list <a href=\"https:\/\/cryptopotato.com\/trezor-users-targeted-in-a-mailchimp-exploit\/\">compromised<\/a> at MailChimp in 2022, pointing users to lookalike download domains built to steal seed phrases.<\/p>\n<p>Two years later, a breach of a third-party support ticketing portal exposed names and email addresses for roughly 66,000 users who had <a href=\"https:\/\/cryptopotato.com\/trezor-users-beware-third-party-email-provider-compromised-in-malicious-attack\">contacted<\/a> Trezor Support since December 2021.\u00a0Both of those exposed contact details, but this one exposed home addresses across multiple countries.<\/p>\n<p>The post <a href=\"https:\/\/cryptopotato.com\/trezor-provider-shipmonk-breach-exposed-order-data-for-13689-hardware-wallet-customers\/\">Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers<\/a> appeared first on <a href=\"https:\/\/cryptopotato.com\/\">CryptoPotato<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>The breach hit 11,742 customers whose names, email addresses, phone numbers, and shipping addresses were all exposed, plus 1,947 whose names, cities, and email addresses were taken. Order numbers were included. Trezor said the records came from orders received between May 10 and August 8, 2026, and named the United States, United Kingdom, Sweden, Colombia, [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-212814","post","type-post","status-publish","format-standard","hentry","category-discovery"],"_links":{"self":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/212814"}],"collection":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=212814"}],"version-history":[{"count":0,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/212814\/revisions"}],"wp:attachment":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=212814"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=212814"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=212814"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}