Threat Intelligence Brief
Curated summary with source attribution
Source: bleepingcomputer.com
Threat Risk: Medium
Victim: Trezor customers
Incident: Data breach of customer PII through a third-party logistics provider.
Impact: Exposure of names, emails, phone numbers, and shipping addresses for approximately 14,000 users.
Attacker: Unidentified threat actors
Analysis: The breach occurred via Trezor’s logistics partner, ShipMonk, which was compromised through a critical SQL injection zero-day vulnerability in the Metabase analytics platform. Attackers accessed PII for nearly 14,000 customers, including names, shipping addresses, and contact details. While Trezor’s internal systems and device security remain intact, the leaked data enables highly targeted phishing campaigns.
Recommendations: Be vigilant against sophisticated phishing attempts impersonating Trezor or financial services.; Enable robust multi-factor authentication (MFA) across all cryptocurrency exchanges and wallets.; Conduct a security audit of third-party vendors to assess supply chain risk management.
Source: BleepingComputer
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-08-13 16:03 UTC
Data breach at third-party shipping provider ShipMonk. Exposure of PII for 13,689 customers, increasing the risk of targeted phishing. The breach occurred at ShipMonk, a third-party logistics provider, rather than within Trezor’s own internal infrastructure. While wallet keys and devices remain secure, the exposure of PII enables highly targeted phishing and impersonation attempts. This incident underscores the critical risk posed by supply chain vulnerabilities in the cryptocurrency hardware ecosystem.
Corroborating source: cryptobriefing.com
Update — 2026-08-13 16:03 UTC
Data breach at a third-party shipping provider Exposure of personal contact and shipping information for nearly 14,000 users The breach occurred at a third-party shipping partner rather than Trezor’s core infrastructure. While wallet seed phrases remain secure, the leak of names and addresses allows attackers to craft convincing social engineering attacks. This highlights the persistent risk of supply chain vulnerabilities in the crypto hardware sector.
Corroborating source: u.today
Update — 2026-08-13 16:24 UTC
A third-party shipping provider suffered a data breach exposing the personal details of over 13,000 Trezor clients. Exposure of names, shipping addresses, email addresses, and phone numbers across multiple countries. The breach occurred at a shipping provider rather than Trezor’s internal systems, highlighting a critical supply chain vulnerability. Exposed PII, including email and phone numbers, provides threat actors with the necessary intelligence to launch sophisticated, targeted attacks against high-value crypto holders. This incident underscores the persistent risk associated with third-party data handling in the digital asset ecosystem.
Corroborating source: news.bloomberglaw.com
Update — 2026-08-13 16:24 UTC
A third-party shipping provider experienced a data breach exposing personal customer information. Exposure of names, addresses, and phone numbers increases the likelihood of targeted phishing and social engineering attacks. The breach occurred at ShipMonk, a shipping partner, rather than within Trezor’s own infrastructure. By linking physical addresses with the knowledge that the victims own hardware wallets, attackers can launch sophisticated social engineering campaigns. This incident highlights the persistent risk of third-party vendor vulnerabilities in the crypto ecosystem.
Corroborating source: tech.yahoo.com
Update — 2026-08-13 16:45 UTC
A data breach at shipping provider ShipMonk exposed the personal information of over 13,000 Trezor customers. The exposure of names, emails, and addresses significantly increases the risk of targeted phishing and social engineering attacks. The incident highlights the persistent risk of supply chain vulnerabilities where third-party vendors handle sensitive customer data. While Trezor’s internal systems and devices remain secure, the leaked PII allows attackers to craft highly convincing social engineering lures. This breach specifically targets customers across several countries, including the US, UK, and parts of Europe and South America.
Corroborating source: trezor.io
Update — 2026-08-13 17:06 UTC
Data breach via third-party fulfillment provider ShipMonk. Exposure of PII for nearly 14,000 customers, increasing the risk of targeted phishing. The breach originated from unauthorized access to ShipMonk, a third-party fulfillment partner, rather than Trezor’s internal systems. While the hardware wallets and private keys remain secure, the exposure of shipping addresses and contact info enables highly targeted social engineering. This incident underscores the critical risk that supply chain partners pose to the security of high-value targets.
Corroborating source: bitcoinmagazine.com
Update — 2026-08-13 17:06 UTC
Data breach exposing customer PII. Exposure of customer names, addresses, and contact details. A data breach at Trezor exposed sensitive customer information, potentially putting users at risk of targeted social engineering or physical threats. The introduction of anonymous shipping is a direct reactive measure to mitigate privacy risks for future customers.
Corroborating source: binance.com
Update — 2026-08-13 17:37 UTC
Data breach at a third-party shipping provider. Exposure of PII for approximately 13,689 customers, increasing risks of phishing and physical theft. The breach occurred at a third-party logistics partner rather than Trezor’s internal infrastructure, leaking PII for nearly 14,000 customers. While hardware wallets remain secure, the exposure of physical addresses and contact info elevates the risk of highly targeted phishing and physical coercion. This incident underscores the persistent danger of supply chain vulnerabilities within the cryptocurrency ecosystem.
Corroborating source: za.investing.com
Update — 2026-08-13 17:37 UTC
Third-party fulfillment partner ShipMonk suffered unauthorized access, leaking PII of nearly 14,000 Trezor users. Increased risk of targeted phishing and social engineering attacks against cryptocurrency holders. The breach occurred at ShipMonk, not within Trezor’s own infrastructure, highlighting the persistent risk of third-party supply chain vulnerabilities. While cryptographic keys and funds remain safe, the exposure of physical addresses and phone numbers allows attackers to conduct highly targeted social engineering. This incident mirrors a broader trend of attackers targeting the periphery of the crypto ecosystem to compromise end users.
Corroborating source: coindesk.com
Update — 2026-08-13 22:15 UTC
Third-party logistics data breach exposing customer PII. Increased risk of targeted phishing and physical harassment for cryptocurrency holders. The compromise occurred at a third-party fulfillment center rather than Trezor’s core infrastructure. While cryptographic keys remain secure, the exposure of physical addresses and contact details creates a significant risk for targeted social engineering and ‘offline’ attacks. This event underscores the systemic risk inherent in the hardware wallet supply chain.
Corroborating source: kucoin.com
Update — 2026-08-13 22:16 UTC
A data breach at a third-party shipping provider exposed customer order information. Personal identifiable information for 13,689 customers was leaked, increasing the risk of targeted phishing. A third-party shipping provider suffered a data breach, leaking PII of over 13,000 Trezor customers. While Trezor’s internal systems and devices remain uncompromised, the leak of physical addresses and contact details enables highly convincing social engineering attacks. This incident highlights the persistent supply chain risks associated with physical product fulfillment.
Corroborating source: tradingview.com
Update — 2026-08-14 16:14 UTC
Data breach exposing personal customer information. Potential for widespread targeted phishing and identity theft. A data breach involving Trezor has resulted in the exposure of sensitive customer personal information. This leak significantly increases the risk of targeted phishing attacks and social engineering campaigns against cryptocurrency holders. The compromise of PII allows attackers to craft highly convincing lures.
Corroborating source: binance.com
Update — 2026-08-14 16:14 UTC
Data breach at third-party logistics provider ShipMonk exposing customer PII. Exposure of names, emails, and addresses for 13,689 customers, heightening the risk of targeted fraud. The breach occurred at ShipMonk, exposing PII of over 13,000 customers across seven countries. Because the leaked data links real identities to cryptocurrency hardware wallet ownership, attackers can craft highly convincing social engineering schemes. This significantly increases the risk of targeted phishing aimed at stealing recovery seeds.
Corroborating source: bitpinas.com
Update — 2026-08-14 18:49 UTC
Unauthorized access to user data resulting in a data breach. Potential for large-scale phishing and social engineering attacks targeting crypto assets. The mention of a data breach at Trezor indicates that sensitive user information may have been compromised. Historically, breaches of hardware wallet providers lead to highly targeted phishing campaigns designed to trick users into revealing their recovery seeds.
Corroborating source: decrypt.co
Update — 2026-08-14 22:03 UTC
Data breach of a third-party shipping partner. Exposure of PII for over 13,000 customers, facilitating potential phishing campaigns. The breach occurred at ShipMonk, a third-party logistics provider, rather than within Trezor’s own infrastructure. The exposure of shipping addresses and contact information significantly increases the risk of highly targeted phishing and social engineering attacks. This incident underscores the critical security risks inherent in supply chain dependencies and third-party data handling.
Corroborating source: scmagazine.com
Update — 2026-08-16 18:56 UTC
Data breach of third-party shipping provider ShipMonk exposing customer PII. 13,689 customers had personal information leaked, significantly increasing the risk of targeted social engineering. The breach occurred at third-party logistics provider ShipMonk, exposing PII including names, phone numbers, and shipping addresses. While Trezor’s core systems and private keys remain secure, the leaked data allows attackers to create highly convincing social engineering campaigns. The ultimate goal of these attacks is likely the theft of wallet recovery seeds through impersonation of support or logistics staff.
Corroborating source: gbhackers.com
Update — 2026-08-17 14:20 UTC
Data breach at shipping partner ShipMonk. Exposure of names, addresses, and contact details for nearly 14,000 cryptocurrency hardware wallet users. While the hardware wallets themselves remain secure, the leak of customer PII creates a significant risk of highly targeted phishing and physical coercion attacks. Threat actors can now identify individuals who likely hold significant crypto assets and know exactly where they reside. This incident underscores the critical risks associated with third-party supply chain data management.
Corroborating source: finance.yahoo.com
Update — 2026-08-23 22:08 UTC
Data breach at fulfillment provider ShipMonk exposing PII of 13,689 customers. Increased risk of highly targeted phishing and social engineering attacks against crypto holders. The breach occurred at ShipMonk, affecting approximately 13,689 Trezor customers by exposing PII including phone numbers and home addresses. While device security and funds remain intact, the availability of order-specific data significantly increases the efficacy of phishing campaigns. This incident highlights the persistent risk posed by third-party supply chain vulnerabilities.
Corroborating source: ryder.id