Trezor Discloses ShipMonk Data Breach Affecting 13,700 Customers Across Seven Countries

Hardware pockets producer Trezor has disclosed a knowledge breach at its third-party logistics associate ShipMonk that uncovered the private info of roughly 13,700 clients throughout seven nations.
The incident, which the corporate described as its first publicity of buyer cellphone numbers and transport addresses since its founding in 2013, impacts new customers within the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who obtained orders inside the 90 days previous to August 8, 2026.
According to Trezor, unauthorized actors accessed ShipMonk’s methods round August 10, 2026, compromising order data that included full names, transport addresses, cellphone numbers, and electronic mail addresses. In whole, 11,742 clients suffered full publicity of those particulars, whereas a further 1,947 skilled partial publicity restricted to call, metropolis, and electronic mail.
The firm emphasised that its personal methods and {hardware} gadgets weren’t compromised, and that the breach scope was restricted by a strict 90-day information retention coverage requiring success companions to delete or anonymize order data after supply.
“We have some tough information to share,” Trezor said in its authentic announcement. “Unfortunately, one in all our transport suppliers has skilled a knowledge breach that uncovered delicate order information.”
All affected customers have been notified immediately by way of electronic mail. Trezor cautioned that leaked private particulars may gasoline extra refined phishing campaigns, with attackers doubtlessly impersonating banks, cryptocurrency exchanges, or Trezor itself to extract delicate info.
Anonymous Delivery and Enhanced Privacy Measures
In response to the incident, Trezor is accelerating the event of an “Anonymous Delivery” service designed to sever the hyperlink between {hardware} pockets purchases and clients’ real-world identities.
The possibility, focused for launch within the European Union by September 2026 and within the United States by year-end, will function a devoted checkout movement permitting customers to register below a nickname or label ID, accumulate parcels from automated lockers, and obtain orders in unbranded packaging with generic sender labels. Carriers will talk pickup codes solely by way of electronic mail or SMS, with transport identifiers mechanically deleted after supply.
Trezor suggested all clients to stay vigilant in opposition to phishing makes an attempt by way of electronic mail, cellphone, or publish, and to by no means enter pockets restoration phrases on web sites or share them with third events. The firm confirmed that ShipMonk has secured the affected methods and hardened its safety posture following the incident, whereas Trezor continues to analyze the total circumstances of the breach.
The publish Trezor Discloses ShipMonk Data Breach Affecting 13,700 Customers Across Seven Countries appeared first on Metaverse Post.
