On August 13, 2026, Trezor said one of its shipping providers, ShipMonk, had unauthorized access to systems that held customer order data. Trezor says its own systems and hardware wallets were not compromised. The risk sits in the data trail around fulfillment: names, email addresses, phone numbers, shipping addresses, cities, and order context that can make scams feel personal.
For TPRM analysts, this is a clean third party breach alert. The business process was simple: a customer buys a physical security product, a logistics partner receives enough data to deliver it, and that partner becomes part of the customer protection surface.
What Happened
ShipMonk told Trezor about unauthorized access
Trezor said ShipMonk notified it on August 10, 2026 that an unauthorized actor accessed systems containing customer data. Trezor published its notice on August 13, 2026 and said the investigation is still ongoing.
Public reporting points to an analytics platform issue
Trezor did not publicly describe the full breach path. BleepingComputer reported that customer notification emails from ShipMonk described exploitation of a vulnerability in Metabase, a third party analytics platform. Treat that as an important lead, but separate it from the facts Trezor has directly confirmed.
What Data Was Affected
Full and partial exposure were both reported
Trezor said 11,742 customers had full exposure of name, email address, phone number, and shipping address. Another 1,947 customers had partial exposure of name, city, and email address. The affected customers were in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
The wallet systems were not involved
Trezor says its operations and services were not affected, its systems were not compromised, and Trezor devices remain secure. That matters because the breach appears to involve order and delivery data, not private keys, wallet backups, firmware, or wallet infrastructure.
The Third Party Angle
Logistics data can become security data
Shipping data is often treated as routine operational data. This incident shows why that view is too narrow. A full name, phone number, email address, and home address can support convincing phishing, phone scams, fake letters, and impersonation of a bank, exchange, courier, or the breached brand.
Retention terms helped limit exposure
Trezor said the breach was limited by a 90 day data storage policy that also applied to fulfillment partners. That is a useful control lesson for TPRM. If a supplier does not need old delivery data, ask why it is still retained and whether it can be deleted or anonymized after the operational need ends.
Practical Protection Steps
What analysts should do first
Start with vendors that sell, ship, repair, replace, or return physical products for your organization or your customers. These suppliers may hold names, phone numbers, email addresses, addresses, order numbers, and support context. That data can be enough to make social engineering more credible.
What to ask the vendor owner
Ask the business owner whether fulfillment partners are listed in the vendor inventory, whether customer data fields are documented, and whether retention rules are written into the contract. Also ask whether incident notices from those partners reach security and privacy teams quickly, not only the operations team.
SAFE TPRM AI Co-Worker is a 100% autonomous TPRM platform powered by 100+ specialized AI agents.
Practical Checklist
- Identify vendors that ship products, replacement parts, devices, cards, documents, or welcome kits
- List the customer fields each fulfillment partner receives
- Confirm whether phone numbers and home addresses are truly required for every shipment
- Check whether order data is deleted or anonymized after the delivery, return, refund, and replacement window closes
- Ask whether the supplier uses analytics, support, warehouse, or reporting platforms that can read customer order data
- Confirm how the supplier monitors unauthorized access to those platforms
- Ask whether active sessions are revoked after a serious platform vulnerability
- Review whether notification duties include phishing, phone scam, and postal scam risks
- Prepare customer support scripts for callers who report suspicious messages after a logistics breach
- Track remediation evidence until the supplier explains what was accessed, what was patched, and what data remains at risk
Analyst Takeaway
This breach is not only a crypto wallet story. It is a reminder that delivery partners can hold sensitive personal data even when they never touch your core platform. TPRM teams should treat fulfillment providers as real data processors, test retention promises, and prepare for fraud risks that continue after the technical incident is contained.
FAQ
What happened in the Trezor ShipMonk breach
Trezor said ShipMonk, one of its shipping providers, had unauthorized access to systems containing customer order data. Trezor said its own systems and wallet devices were not compromised.
How many customers were affected
Trezor said the incident affected about 13,689 customers. The larger group had full contact and shipping exposure, while a smaller group had name, city, and email exposure.
What data was exposed
The confirmed fields include names, email addresses, phone numbers, shipping addresses, cities, and order related information where held by ShipMonk for delivery support.
Why does this matter for third party risk teams
A logistics provider may hold data that feels operational, but it can become security data when attackers use it for phishing, phone scams, physical letters, or impersonation.
What should TPRM analysts ask vendors now
Ask whether vendors share customer contact data with fulfillment partners, how long that data is retained, what breach notice paths exist, and whether scam monitoring is part of the response plan.