Back to Blog
high severity · 4 min read Unverified claim — what this is

Did the Trezor ShipMonk breach expose my name and home address?

If you have an account with Did the Trezor ShipMonk, here’s what is being claimed, and what it would mean for you.

Did the Trezor ShipMonk was listed on a ransomware/extortion leak site. The group claims to have stolen internal data. This is the group's claim, not a confirmed finding.

Did the Trezor ShipMonk breach expose my name and home address?

On 13 August 2026, Trezor confirmed that ShipMonk, one of the companies that ships its devices, had unauthorized access to systems holding customer order data. ShipMonk told Trezor on 10 August. About 13,689 customers who received orders in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy or Portugal were affected. Trezor said its own systems and devices were not involved, and the secret keys and recovery words that control a wallet were not exposed.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Of those people, 11,742 had full names, email addresses, phone numbers, shipping addresses and order numbers taken. Another 1,947 had names, city and email addresses taken. Trezor emailed affected customers from [email withheld] and says anyone who did not get that email is not part of this incident. A later update on its blog said some of the 1,947 partial records may include older orders, beyond ShipMonk’s usual 90-day retention window. Trezor is still checking those dates with ShipMonk.

The keys were not the prize

Almost every report of this incident opens with the same line: no wallets were opened, no recovery words left Trezor, the devices themselves were never in anyone else’s hands. That is true. It is also the least useful fact if you are trying to decide whether this changes anything for you.

What left ShipMonk is a list of named people — most of them at a specific home address — documented as Trezor customers who had a device shipped to them. For 11,742 of them the list also has a phone number and an order number. That is not a password dump. It is a ready-made script for someone who wants to sound like Trezor, a courier, a bank or an exchange, and who already knows where you live and that you own this kind of device.

Trezor itself said this is the first time customer phone numbers and shipping addresses have been exposed in its history. It warned of more convincing phishing: fake emails, phone calls, letters, and people impersonating Trezor, banks or exchanges. Trezor said it has no confirmed cases of the data being misused so far. The copy that was taken still cannot be pulled back.

What to actually expect

  • If you were in this breach, the genuine notice already came from [email withheld]. Trezor says that if you did not receive that email, you are not affected. A later message that offers to “check whether you were included,” “secure your device,” or confirm a delivery is using the news, not helping you.
  • Expect contact that already knows something real — your name, your city or street, a recent order number, your phone number. That is what makes this different from ordinary junk mail. The dangerous messages will feel specific because they are.
  • It will not only be email. Trezor specifically flagged calls and letters, and people pretending to be Trezor, a bank or an exchange. A voice that already has your address is harder to shrug off than a clumsy phishing email.
  • If you are in the smaller group of 1,947, do not treat “only name, city and email” as a miss. That is still enough to write a convincing message, and Trezor has not finished confirming how far back those records go.

What you can and cannot fix

The records that were taken cannot be recalled. If your name, email, phone number or home address was sitting in ShipMonk’s systems, that copy is out. Trezor cannot delete it from whoever got in. You cannot either. An address, once tied to the fact that a Trezor was shipped there, stays tied.

What still helps, in this order:

  • Treat unsolicited contact about this incident as hostile. Do not confirm an address, read back an order number, install anything, or discuss a recovery phrase or PIN with anyone who reached out to you. If you want Trezor’s own notice, type the company’s site into your browser yourself. Do not follow a link in a message.
  • Tell the people who share your home. They are the ones who will pick up a phone or open a letter. They should know a stranger may already have your name and address, and that nobody needs a recovery phrase, a PIN, or “verification” of your order because of this incident.
  • Shrink the rest of your public footprint. A bare shipping record becomes much more useful when it is joined to a people-search listing that already publishes relatives, extra phone numbers, an employer and previous addresses. Those listings, unlike the ShipMonk data, can actually be taken down. Removing them is the one part of this you can still change.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Did the Trezor ShipMonk is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed
Last reviewed August 8, 2026
Affected Unconfirmed
Data exposed Full namesEmail addressesPhone numbersShipping addressesOrder numbersCity
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email