Investigation · Customer Order Data

Trezor / ShipMonk Data Breach Investigation

Hall Attorneys is evaluating potential claims after Trezor said a breach at shipping provider ShipMonk exposed customer order data. The latest disclosure adds approximately 67,000 U.S. customers who ordered between November 2019 and August 2021. Trezor says its systems and devices were not compromised, but the exposed contact and delivery information may enable convincing scams and other targeted threats.

Additional U.S. customers
~67,000

latest scope disclosed September 4, 2026

Reported total
~80,689

67,000 additional plus 13,689 initially reported

Older order window
2019–2021

November 2019 through August 2021

Could this be me?

Could my Trezor order be involved?

The clearest indicator is a direct notification from Trezor. Order timing and fulfillment records can also help identify a possible connection, particularly for U.S. customers who ordered between November 2019 and August 2021 or customers included in Trezor's August notice.

  1. Trezor emailed you about the ShipMonk incident

    Preserve the complete message, its headers, and any follow-up. Verify the sender and navigate to Trezor's official website independently rather than using an unexpected link or phone number.

  2. You ordered directly from Trezor in the United States

    The latest disclosure concerns approximately 67,000 U.S. customers whose orders date from November 2019 through August 2021. Save the order confirmation, invoice, delivery record, and the address used at the time.

  3. You received a Trezor order shortly before August 8, 2026

    Trezor's initial notice covered recent orders delivered in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The company initially reported 11,742 fully exposed and 1,947 partially exposed customers.

  4. Your records mention ShipMonk

    Check shipping notices, tracking pages, labels, return records, support messages, and delivery updates for ShipMonk or another fulfillment-provider reference tied to the Trezor order.

  5. You bought through a reseller or marketplace

    A purchase from Amazon or another independent retailer does not necessarily appear in Trezor's direct-order data. Preserve the receipt and identify the actual seller and shipper before assuming a connection.

  6. You received a wallet-themed call, email, text, or letter

    Keep the communication, envelope, caller information, and any related account alerts. Do not share a wallet backup, recovery seed, PIN, passphrase, password, or remote access to a device.

Check your records

Check orders and notices without exposing your wallet

Search your own records for the company and fulfillment names. Use official Trezor channels to verify a notice, and never enter a wallet backup into a website or disclose it to someone contacting you.

TrezorShipMonkorder confirmationsecurity incident
  • Locate the order date, delivery country and address, seller, shipper, and order number.
  • Preserve Trezor's notice and any suspicious email, call, text, or physical letter.
  • Write down whether the disclosed address is still current and whether suspicious activity followed the notice.
  • Do not share a seed phrase, wallet backup, PIN, passphrase, password, or cryptocurrency balance through an intake form.

Answer at a glance

What happened in the Trezor / ShipMonk breach?

Trezor says ShipMonk, one of its shipping providers, informed it on August 10, 2026 of unauthorized access to systems containing customer order data. Trezor's August 13 notice initially identified 11,742 customers with full exposure and 1,947 customers with partial exposure.

On September 4, Trezor disclosed that ShipMonk had provided a further update two days earlier. According to Trezor, approximately 67,000 additional U.S. customers who ordered between November 2019 and August 2021 had names, email addresses, phone numbers, shipping addresses, and order numbers exposed.

Trezor says it had repeatedly requested and received written assurances that older order data was deleted in accordance with its contract and data policy, but later learned the records remained in ShipMonk's systems. The public record reviewed for this page does not yet establish why the data remained, the precise unauthorized-access period, or whether the reported counts contain any overlap.

Trezor says its systems, products, and devices were not compromised. The reported data does not include wallet backups or recovery seeds, but contact information tied to a hardware-wallet purchase may support highly tailored phishing, impersonation, fraudulent letters, or physical-security threats.

This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.

  1. Older U.S. order records retained

    Trezor says the approximately 67,000 additional customers placed orders during this period and that ShipMonk retained records Trezor understood had been deleted.

  2. ShipMonk notifies Trezor

    Trezor says its shipping provider reported unauthorized access to systems containing customer data.

  3. Trezor publishes its initial notice

    Trezor initially reported 11,742 customers with full exposure and 1,947 with partial exposure, or approximately 13,689 customers in total.

  4. ShipMonk reports a broader scope

    Trezor says ShipMonk informed it that older U.S. order records were also involved in the incident.

  5. Approximately 67,000 more customers disclosed

    Trezor publicly announced the additional U.S. customer group and said all newly affected customers had been emailed directly.

Reported data categories

What information was involved?

Trezor describes the exposed information as fulfillment and order data held by ShipMonk. The combination can reveal both how to contact a customer and where a hardware wallet was delivered.

Important distinction

Trezor says its own systems and devices were not compromised. Public reporting reviewed for this page does not identify wallet backups, recovery seeds, private keys, wallet balances, passwords, or payment-card numbers as exposed data.

Identity information
Customer names
Contact information
Email addresses and phone numbers
Delivery information
Shipping addresses associated with Trezor orders
Transaction context
Order numbers and an apparent connection to a Trezor purchase

Who may want to contact us

Trezor customers whose orders were handled by ShipMonk

The latest group consists of approximately 67,000 U.S. customers who ordered between November 2019 and August 2021. Trezor's initial disclosure also covered recent customers in seven countries. A direct Trezor notice is the strongest public indicator of inclusion.

U.S. customers who ordered directly from Trezor between November 2019 and August 2021 and received an incident notice

Customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal included in Trezor's August 2026 notice

People whose current or former home address was associated with an affected Trezor order

Affected customers who receive targeted wallet-themed phishing, fraudulent calls or letters, impersonation attempts, or physical threats

People who spend time or money responding to misuse connected to the exposed order information

What to preserve

Keep the notice, order record, and evidence of targeted contact

Preserve enough information to document the affected transaction and any resulting harm, but do not send wallet credentials, a recovery seed, cryptocurrency holdings, passwords, or complete financial-account information through an ordinary contact form.

Trezor notices and updates

Keep the complete incident email, its headers, any envelope, the date received, and later updates. Save a copy before deleting or reporting a suspicious message.

Order and delivery records

Preserve the invoice, order confirmation, order number, seller, shipping notices, tracking history, delivery country, and address used at the time.

Proof of the fulfillment provider

Save labels, return instructions, tracking pages, or support messages that identify ShipMonk or another shipping provider associated with the order.

Suspicious digital communications

Keep wallet-themed emails, texts, caller details, fake support messages, account alerts, and screenshots of websites or profiles used in an impersonation attempt.

Physical mail or threats

Preserve fraudulent letters and envelopes and document any threat. Contact local emergency services if there is an immediate safety concern.

Time, expense, and loss

Maintain a dated log of time spent securing accounts, professional or security expenses, lost funds, replacement costs, and other concrete effects.

Investigation focus

Issues under review

Hall Attorneys is reviewing the unauthorized access, retention of older order data, notice and protective measures, and any phishing, fraud, physical-security concern, expense, or other harm experienced by affected customers.

  1. How and when unauthorized access to the ShipMonk systems occurred and when it was detected
  2. Whether approximately 80,689 is the complete count of affected customers and whether any records overlap
  3. Why 2019–2021 Trezor order data remained available after the reported deletion assurances
  4. What systems, backups, repositories, vendors, or downstream recipients held or received the customer data
  5. Whether the affected-person notices accurately identify each person's data and provide appropriate protective support
  6. Whether exposed information has been used for targeted phishing, impersonation, fraudulent letters, account compromise, theft, or physical threats
  7. What time, expense, loss, privacy harm, or safety measures affected customers have experienced

Public records reviewed

Sources for the Trezor / ShipMonk incident

The sources below include Trezor's initial public notice and contemporaneous reporting on the September scope expansion. The investigation remains ongoing and the public account may change.

Contact the firm

Did Trezor notify you about the ShipMonk breach?

Contact Hall Attorneys with your order date and country, whether you received Trezor's notice, whether the delivery address remains current, and a summary of suspicious contact, expense, or loss. Do not send a recovery seed, wallet backup, PIN, passphrase, password, cryptocurrency balance, or complete financial record in an initial message.

Contact Hall Attorneys

Frequently asked questions

Trezor / ShipMonk breach FAQ

How many Trezor customers were affected?

Trezor initially reported approximately 13,689 affected customers. On September 4, 2026, it said approximately 67,000 additional U.S. customers were affected, bringing the reported total to approximately 80,689 if the groups do not overlap.

Which Trezor orders are included in the latest disclosure?

Trezor says the newly disclosed group consists of U.S. customers who ordered between November 2019 and August 2021. Its August notice concerned a separate recent-order group in the United States and six other countries.

What information was exposed?

Trezor says the newly identified records contained names, email addresses, phone numbers, shipping addresses, and order numbers.

Were Trezor devices, private keys, or recovery seeds compromised?

Trezor says its own systems and devices were not compromised. The public sources reviewed for this page do not identify private keys, recovery seeds, wallet backups, PINs, passphrases, wallet balances, or payment-card numbers as exposed data.

How can I tell whether I was affected?

Trezor says it emailed affected customers directly. Verify any message through Trezor's official website rather than an unexpected link, and preserve the notice and your order records. Owning a Trezor device alone does not prove inclusion.

What should an affected customer avoid sharing?

Never share a wallet backup, recovery seed, PIN, passphrase, password, remote device access, or cryptocurrency balance with someone who contacts you. Trezor says it will never ask for a wallet backup.

Has Hall Attorneys filed a Trezor or ShipMonk lawsuit?

No. This page describes an investigation by Hall Attorneys and does not state that the firm has filed a lawsuit concerning Trezor or ShipMonk.

Attorney Advertising

Hall Attorneys is not affiliated with Trezor or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.