Full Report
Even if your hardware is secure, quantum-ready, encrypted, and future-proof, no one is immune to a supplier letting the side down
Analysis Summary
# Incident Report: Trezor Logistics Provider Data Breach
## Executive Summary
Trezor, a leading hardware cryptocurrency wallet manufacturer, experienced a third-party data breach via its logistics partner, ShipMonk. The incident resulted in the exposure of personal identification information (PII) for over 13,000 customers, including names, phone numbers, and physical shipping addresses. While the hardware devices themselves remain secure, the breach poses significant risks for targeted phishing and potential physical "home invasion" attacks against crypto holders.
## Incident Details
- **Discovery Date:** Approximately August 2026 (Reported Aug 14, 2026)
- **Incident Date:** May 10, 2026 – August 8, 2026 (Primary window)
- **Affected Organization:** ShipMonk (Logistics partner for Trezor)
- **Sector:** Cryptocurrency / E-commerce / Logistics
- **Geography:** Global (Primarily US, UK, Sweden, Colombia, Brazil, Italy, and Portugal)
## Timeline of Events
### Initial Access
- **Date/Time:** On or before May 10, 2026.
- **Vector:** Third-party supply chain compromise.
- **Details:** Attackers gained unauthorized access to the systems of ShipMonk, Trezor’s logistics provider responsible for order fulfillment.
### Lateral Movement
- **Details:** Specifics of movement within ShipMonk’s internal network were not disclosed; however, the attackers gained access to databases containing Trezor customer order history.
### Data Exfiltration/Impact
- **Details:** PII for 11,742 customers (Names, emails, phone numbers, shipping addresses) and 1,947 additional customers (Names, cities, emails) was accessed.
### Detection & Response
- **How it was discovered:** Initial findings identified a 90-day window of exposure, later expanded upon further investigation.
- **Response actions taken:** Trezor verified the timeframe with the partner, notified affected customers directly, and issued a public advisory regarding phishing risks.
## Attack Methodology
- **Initial Access:** Compromise of third-party service provider (ShipMonk).
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Likely gained through the logistics provider’s database or API.
- **Discovery:** Targeted search for Trezor customer records.
- **Collection:** Data gathering of customer shipping and contact details.
- **Exfiltration:** Transfer of customer databases from the logistics provider's environment.
- **Impact:** Data breach leading to high-risk phishing and physical security threats.
## Impact Assessment
- **Financial:** No direct theft of funds reported, but high potential for future financial loss via social engineering.
- **Data Breach:** Exposure of 13,689 records containing sensitive PII.
- **Operational:** Disruption of shipping verification processes and increased support load.
- **Reputational:** Significant damage to Trezor's "secure" brand image; public mockery by competitors (Cake Wallet).
## Indicators of Compromise
- **Network indicators:** None disclosed (Third-party breach).
- **File indicators:** None disclosed.
- **Behavioral indicators:** Unusual access patterns within ShipMonk’s database environments; increase in phishing lures reported by customers.
## Response Actions
- **Containment measures:** Investigation into ShipMonk's data retention policy compliance.
- **Eradication steps:** Verification of data deletion/anonymization for records older than 90 days.
- **Recovery actions:** Launching an "Anonymous Delivery" project to decouple physical identity from hardware purchases.
## Lessons Learned
- **Supply Chain Fragility:** Even "unhackable" hardware is vulnerable to leaks at the logistics layer.
- **Data Retention Enforcement:** Third-party partners may fail to adhere to 90-day anonymization/deletion policies.
- **Physical Risk:** In the crypto industry, a home address leak is a physical security threat, not just a digital one.
## Recommendations
- **Implement "Anonymous Delivery":** Use automated delivery lockers and aliases to prevent PII storage.
- **Stricter Vendor Audits:** Conduct regular audits of logistics partners to ensure data retention policies are technically enforced, not just contractually agreed upon.
- **Customer Education:** Advise customers to use "burner" emails and PO Boxes for hardware wallet purchases.
- **Defensive Communication:** Encourage customers to be hyper-vigilant for "Evil Maid" attacks or physical extortion attempts following the leak of their home addresses.