Trezor Discloses Data Breach Affecting 14,000 Customers
Cryptocurrency hardware wallet manufacturer Trezor has announced that the personal data of nearly 14,000 customers has been leaked following a cyberattack on one of its suppliers. The attack does not affect the security of the devices, but it could expose users to targeted phishing attacks.
What Happened
Trezor, a leading name in the cryptocurrency hardware wallet industry, has publicly disclosed a significant data breach affecting thousands of its customers. According to a statement released on August 13, 2026, the incident did not originate from Trezor's own systems but occurred after its shipping and logistics partner, ShipMonk, suffered a cyberattack. As a result of this attack, the personal information of nearly 14,000 Trezor customers fell into the hands of cybercriminals. This development once again highlights how seriously supply chain attacks can impact the cryptocurrency ecosystem. Although Trezor emphasized that the breach does not directly affect its own infrastructure or the security of its products, it issued strong warnings that the leaked data could be used in phishing attacks targeting its customers.
According to Trezor's timeline of the event, the logistics firm ShipMonk informed Trezor on Monday, August 10, 2026, about unauthorized access to their systems. Following this notification, Trezor immediately launched an investigation to identify the affected customers and determine the scope of the leak. The analysis revealed that the attack impacted customers from specific geographic regions and within a certain time frame. Aware of the potential impact of such an incident on customer trust, the company opted for a transparent communication process, sharing the details of the breach in a blog post. This situation serves as a concrete example of how a weak link in a company's ecosystem can pose a risk to its entire user base, even if the company itself is not directly attacked.
Data Compromised
The data accessed by the cyberattackers through ShipMonk's systems includes sensitive personal information of customers. However, Trezor has strongly underlined that the most critical information—the private keys or seed phrases that protect users' crypto assets—remains secure. While the leaked data does not lead to direct financial loss, it contains highly valuable information for fraudulent activities.
The customers affected by the breach are divided into two groups:
- 11,742 Customers (Full Exposure): Customers in this group had their comprehensive information leaked, including full name, shipping address, email address, and phone number. This data allows attackers to craft highly convincing and personalized phishing scenarios.
- 1,947 Customers (Partial Exposure): For this group, the compromised data includes their full name, city, and email address. More detailed information, such as the full shipping address or phone number, was not exposed for this group.
The combination of this data is a powerful weapon for attackers. For instance, knowing a customer's name, email address, and the date range of their Trezor order makes it easier to deceive them with fake messages like "There's a problem with your order" or "Update your account security." Attackers can use this information to send fake emails, make fraudulent phone calls, send scam letters, and even impersonate officials from banks, crypto exchanges, or Trezor itself.
How the Attack Occurred
Trezor has clearly stated that the attack did not happen on its own systems. The epicenter of the incident is ShipMonk, the third-party service provider that manages Trezor's logistics and shipping processes. But the attack chain doesn't end there. The breach into ShipMonk's systems was due to a critical security vulnerability in another third-party software they use: an analytics platform called Metabase.
The technical origin of the attack was detailed more clearly in the notification emails sent by ShipMonk to affected customers. On August 6, 2026, Metabase informed ShipMonk that a vulnerability in its software had been exploited by an unauthorized party. This vulnerability was a "zero-day," a security flaw unknown to the software developer or for which no patch had been released at the time of exploitation. The attackers exploited a critical SQL injection vulnerability in the Metabase platform to gain administrator access to ShipMonk's Metabase instance. This level of access allowed them to reach the databases containing customer order data.
This incident appears to be part of a broader wave of attacks targeting the Metabase platform. Other companies, such as laptop maker Framework and online form builder Tally, had also announced data breaches due to the same Metabase vulnerability. According to information obtained by BleepingComputer, the logistics firm ShipMonk also received extortion emails from the notorious extortion gang ShinyHunters after the attack. This indicates that the attackers are not only stealing data but also using it for financial extortion.
This is not the first security issue Trezor has faced due to its supply chain. The company also disclosed a data breach through a third-party service provider in January 2024.
Who Was Affected
The data leak targets Trezor customers who placed orders within a specific time frame and from certain countries. If you ordered a hardware wallet from Trezor between May 10, 2026, and August 8, 2026, and reside in one of the countries listed below, you are likely affected by this breach.
The countries with affected customers are:
- United States
- United Kingdom
- Sweden
- Colombia
- Brazil
- Italy
- Portugal
In total, it has been confirmed that the data of 13,689 customers was leaked. A significant portion of these customers, approximately 11,742, are at a higher risk due to the full exposure of their personal and contact information.
What You Can Do
Your Trezor device and the crypto assets on it are safe. However, your leaked personal data can make you vulnerable to targeted fraud attempts. Therefore, taking the following steps is crucial:
- Be Vigilant Against Phishing Attacks: Be extremely skeptical of emails, text messages, and phone calls that appear to be from Trezor, ShipMonk, shipping companies, or crypto exchanges. Attackers can use your leaked information to make these communications look very authentic.
- Never Share Your Recovery Seed: This is the most important rule. Trezor or any other legitimate organization will never ask you for your 12 or 24-word recovery seed phrase or your PIN code. Anyone asking for this information is a scammer.
- Do Not Click on Unofficial Links: Avoid clicking links or downloading attachments in incoming messages. Always navigate directly to the company's official website to conduct any business.
- Check Sender Information: Carefully verify who an email is from. Scammers often use fake email addresses that look very similar to official ones (e.g., [email protected]).
- Do Not Install Unsolicited Software: Absolutely refuse any requests to install software under pretexts like a "security update" or "wallet verification." Trezor firmware updates are only performed through the official Trezor Suite application.
What the Company Says
Trezor prioritized transparency in its statement regarding the incident. In a blog post published on Thursday, the company stated that its own operations and services were not affected by the breach and that its systems were not compromised. Most importantly, it reiterated that all Trezor devices remain secure.
The company's statement included the following: "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts. Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor."
Trezor urged affected customers to be vigilant and to treat any communication requesting personal information with suspicion. A Trezor spokesperson contacted by BleepingComputer for more information about the incident was not immediately available for comment.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.