Full Report
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping provider and logistics partner, got hacked. [...]
Analysis Summary
# Incident Report: Trezor Customer Data Exposure via ShipMonk Breach
## Executive Summary
Hardware wallet manufacturer Trezor experienced a secondary data breach affecting approximately 13,689 customers following a compromise at ShipMonk, its third-party logistics provider. Unauthorized access to ShipMonk’s systems resulted in the exposure of personally identifiable information (PII) including names and shipping addresses. Trezor’s internal systems and hardware devices remain uncompromised, but affected users face an elevated risk of targeted phishing and social engineering.
## Incident Details
- **Discovery Date:** August 10, 2026
- **Incident Date:** May 10, 2026 – August 8, 2026
- **Affected Organization:** ShipMonk (Third-party provider for Trezor)
- **Sector:** Cryptocurrency Hardware / Logistics & Supply Chain
- **Geography:** United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal
## Timeline of Events
### Initial Access
- **Date/Time:** Approximately May 10, 2026
- **Vector:** Unauthorized access to ShipMonk’s internal systems.
- **Details:** Attackers gained entry to the systems used by the logistics partner to manage customer orders and shipping details.
### Lateral Movement
- **Details:** Specifics regarding internal movement within ShipMonk’s network were not disclosed in the Trezor public statement.
### Data Exfiltration/Impact
- **Date Range:** Data spanning orders placed/processed between May 10 and August 8, 2026.
- **Impact:** Exposure of PII for 11,742 customers (Full: name, email, phone, address) and 1,947 customers (Partial: name, city, email).
### Detection & Response
- **August 10, 2026:** ShipMonk notified Trezor of the unauthorized access.
- **August 13, 2026:** Trezor issued a public disclosure and blog post to warn affected customers.
- **Response:** Trezor initiated a customer notification campaign and began monitoring for related phishing campaigns.
## Attack Methodology
- **Initial Access:** Compromise of third-party service provider (Supply Chain Attack).
- **Persistence:** Not disclosed; access maintained for approximately three months.
- **Collection:** Automated or manual extraction of customer order databases.
- **Exfiltration:** Theft of customer shipping and contact records.
- **Impact:** Information disclosure leading to downstream phishing and physical security risks for crypto-asset holders.
## Impact Assessment
- **Financial:** No direct theft of funds reported; however, increased risk of targeted "seed phrase" phishing.
- **Data Breach:** ~13,689 customer records containing names, emails, phone numbers, and physical shipping addresses.
- **Operational:** Minimal disruption to Trezor’s core operations; internal systems remained isolated.
- **Reputational:** Negative impact due to recurring third-party breaches (following a similar incident in January 2024).
## Indicators of Compromise
- **Network indicators:** None disclosed (Incident occurred on third-party infrastructure).
- **File indicators:** N/A.
- **Behavioral indicators:** Potential increase in phishing emails from domains mimicking `trezor[.]io` or shipping updates.
## Response Actions
- **Containment:** ShipMonk addressed the unauthorized access on their systems.
- **Eradication:** Trezor confirmed no breach of its own infrastructure.
- **Recovery:** Public advisory issued; direct communication sent to the 13,689 affected individuals.
## Lessons Learned
- **Supply Chain Vulnerability:** Third-party logistics providers remain a high-value target for attackers looking to deanonymize cryptocurrency users.
- **Data Minimization:** There is a critical need to evaluate how long PII is retained on third-party shipping platforms after an order is completed.
- **Recurring Risk:** This incident follows a January 2024 breach (Support ticketing portal), highlighting that the "weakest link" is often external integrations rather than the product itself.
## Recommendations
- **Vendor Auditing:** Conduct rigorous security audits of logistics partners, specifically regarding their database encryption and access control policies.
- **Automated Data Deletion:** Implement API-driven workflows to automatically purge customer shipping data from partner systems 30 days after successful delivery.
- **Customer Education:** Continuously remind users that Trezor will never ask for a 24-word recovery seed via email or phone.
- **Encourage Stealth Shipping:** Advise high-value customers to use PO boxes or business addresses rather than home addresses for hardware wallet deliveries.