Trezor discloses data breach affecting nearly 14,000 customers
I'll pull the BleepingComputer report and the post-writing rules so the paragraphs stay factual and match the house style.The pulse already has this story.…
By Dillip Chowdary • Aug 14, 2026 • Source: BleepingComputer
What happened
I'll pull the BleepingComputer report and the post-writing rules so the paragraphs stay factual and match the house style.The pulse already has this story. I'll pull the BleepingComputer piece and Trezor's own disclosure so the paragraphs stay on verified numbers.Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 customers after ShipMonk, its shipping and logistics provider, was hacked. In a Thursday blog post, Trezor said ShipMonk notified it on Monday, August 10, 2026 that an unauthorized party had reached systems holding customer order data. The company split the impact into 11,742 customers with full exposure of name, email, phone number, and shipping address, and 1,947 customers with partial exposure of name, city, and email, about 13,689 people in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10 and August 8, 2026. Trezor said its own systems were not compromised, operations and services were unaffected, and Trezor hardware wallets remain secure. It is the first time since Trezor was founded in 2013 that customer phone numbers and shipping addresses have been exposed.
The compromise did not start on Trezor firmware or the Trezor e-shop. BleepingComputer reviewed ShipMonk notices stating that on August 6, 2026, Metabase told ShipMonk an unauthorized party had exploited a vulnerability in Metabase software to reach data tied to ShipMonk's account and its customers. Metabase is a third-party analytics platform; prior reporting from the same outlet said attackers used a critical SQL injection zero-day against customer Metabase instances, obtained administrator access, and stole data. Metabase said it patched the flaw and invalidated active sessions. ShipMonk said it opened a technical investigation with external specialists. Trezor did not itself describe the exploit. On Trezor's side the window was supposed to be narrow: a 90-day retention policy requires fulfillment partners to delete or anonymize order data 90 days after delivery, leaving ShipMonk with only the fields needed to ship a parcel, including name, email, order number, phone, and address. Trezor later cautioned that the 1,947 partial records may include older orders and is checking that claim with ShipMonk.
The technical detail

For engineers who ship a physical security product, the lesson is that the secure element is not the whole system. A Trezor is built so private keys never leave the device, and that property was not broken here. What leaked is a list of people who just bought a hardware wallet, paired with home address, phone, and email. That is enough to run phishing by mail, voice, or inbox and to impersonate Trezor, a bank, or an exchange. Trezor told customers never to type a wallet backup into a website or share it with anyone. Anyone running commerce plus a third-party logistics warehouse should treat fulfillment PII as a customer-identity store, put deletion into the contract, and treat analytics tools attached to that warehouse as in-scope for the same data class.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Why it matters for builders
This is not Trezor's first third-party leak. In January 2024 the company disclosed that attackers reached a support ticketing portal and may have exposed names, usernames, and emails for 66,000 people who had contacted Trezor Support since December 2021; those addresses were later used in phishing aimed at 24-word recovery seeds. Rival Ledger has spent years dealing with phishing and extortion fed by its own earlier e-commerce leak. The same Metabase zero-day also hit laptop maker Framework and form builder Tally. BleepingComputer reported that ShipMonk has received extortion emails from the ShinyHunters gang. Valve separately told European Steam hardware customers that attackers stole data after compromising CEVA Logistics. Fulfillment and support vendors are a repeating path into consumer hardware, not a one-off at Trezor.
Market and competitive context
Affected buyers should treat any message that cites a recent Trezor order as hostile until it is confirmed on Trezor's own blog and official channels. Trezor said it emailed everyone in this incident from its support address and that people who received no such mail are not in the dump. The next factual checkpoint is whether ShipMonk's 90-day deletion actually held for the 1,947 partial records. Trezor is also preparing Anonymous Delivery, with dedicated checkout, locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery, targeted at the EU by September 2026 and the United States by the end of 2026. Teams that point Metabase at production customer tables should treat that BI instance as part of the attack surface and assume this class of SQL injection is being farmed.
What to watch next
Open questions remain. Trezor has not said how ShipMonk's Metabase instance was reachable or whether the stolen rows have been listed for sale. The disclosure does not confirm misuse of the new Trezor records, but the 2024 ticket-portal leak showed that email-only data was already enough to run seed-phrase phishing; phone numbers and street addresses make those lures sharper. Trezor cannot drop carrier-required fields for a physical device, so it also suggests an anonymous email, crypto or a disposable card at checkout, or a P.O. box. ShipMonk's investigation is still open. The test over the coming weeks is whether affected customers see a wave of Trezor-branded phishing like the one that followed the 2024 incident, and whether Trezor revises the count if the 90-day wipe was incomplete.
Advertisement
🔎 More interesting news
- Meta Open-Sources Muse Glimmer: A 30B Local Agentic Model Optimised for On-Device…
- Google announces Gemini 3.7 Flash just three weeks after previous release
- SpaceXAI debuts Grok 4.6, overtaking Kimi K3's performance and matching GPT-5.6 Sol for…
- Writer introduces new AI model and upgraded harness to contain token costs
- Today's full Tech Pulse briefing →