The Trezor breach did not originate from the company’s systems, but from logistics partner ShipMonk. The attack exposed order details for nearly 14,000 customers and creates a new risk for targeted phishing attempts.
According to BleepingComputer, Trezor was notified on August 10 that its delivery provider had received unauthorized access. The company says its own systems were not compromised and that users’ devices and funds remain safe.
See also: Vercel: Data breach exposes customer credentials

What we know about the Trezor breach
The report covers orders delivered between May 10 and August 8, 2026, to customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The countries are connected to ShipMonk fulfillment centers, as documented on Trezor’s support page.
Trezor splits the affected users into two groups. In 11,742 cases, the name, shipping address, email address, and phone number were exposed. In another 1,947 cases, the exposure was partial, including name, city, and email address.
This data does not include passwords, seed phrases, or information required to directly move funds. However, the combination of name, address, and phone number gives scammers enough context to craft convincing messages, phone calls, or letters.
The update only concerns information used to ship products. Trezor claims that the functionality of its services was not affected and that there is no indication that the attackers gained access to data protecting digital assets.
This case falls into a familiar pattern of attacks on third-party providers. Logistics companies need contact and address information to fulfill an order, but the same data takes on a different value when connected to a hardware wallet manufacturer.
This means that victims should not evaluate a communication solely on whether it contains correct information. Attackers can copy logos, use similar addresses, and claim a real order, while the ultimate goal remains to reveal the seed or install malware.

Why the Trezor breach increases the risk of phishing
The main consequence is not access to the device, but the possibility of personalized deception. A message that knows the delivery address or the fact that someone ordered a hardware wallet can appear as a supposedly shipping notification, account verification, or urgent security update.
official guidance on scams and phishing is clear: no message should lead the user to reveal their wallet backup, PIN, password, or verification code. The company does not request a recovery seed via email, SMS, phone, or messaging apps.
The SecNews technical team points out that the presence of actual order details does not prove the authenticity of a message. The safe practice is to independently type the official trezor.io address, without using links or phone numbers included in the communication.
See also: SHub Reaper: New infostealer disguises itself as legitimate Apple tools

What affected users should do
Customers who have received a notification from Trezor should treat any subsequent communication with increased caution. There is no need to change the recovery seed because shipping details were leaked, but it is necessary to check the sender's address and avoid any requests for secret details.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Any request to enter a seed phrase on a website, connect a device for "emergency recovery" or install software from an unknown link should not be followed. In case of doubt, communication should be discontinued and assistance should only be sought from the official support center.
See also: GlassWorm malware hides RAT in Chrome extension
The Trezor breach shows that even when the primary provider and the device itself remain immune to attack, supply chain data can be turned into a social engineering tool. The key lesson for every user is simple: no one should obtain the recovery seed, no matter how convincing the communication seems.
