Did the Trezor ShipMonk breach expose my name and home address?
If you have an account with Did the Trezor ShipMonk, here’s what is being claimed, and what it would mean for you.
Did the Trezor ShipMonk was listed on a ransomware/extortion leak site. The group claims to have stolen internal data. This is the group's claim, not a confirmed finding.
On 13 August 2026, Trezor confirmed that ShipMonk, one of the companies that ships its devices, had unauthorized access to systems holding customer order data. ShipMonk told Trezor on 10 August. About 13,689 customers who received orders in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy or Portugal were affected. Trezor said its own systems and devices were not involved, and the secret keys and recovery words that control a wallet were not exposed.
Of those people, 11,742 had full names, email addresses, phone numbers, shipping addresses and order numbers taken. Another 1,947 had names, city and email addresses taken. Trezor emailed affected customers from [email withheld] and says anyone who did not get that email is not part of this incident. A later update on its blog said some of the 1,947 partial records may include older orders, beyond ShipMonk’s usual 90-day retention window. Trezor is still checking those dates with ShipMonk.
The keys were not the prize
Almost every report of this incident opens with the same line: no wallets were opened, no recovery words left Trezor, the devices themselves were never in anyone else’s hands. That is true. It is also the least useful fact if you are trying to decide whether this changes anything for you.
What left ShipMonk is a list of named people — most of them at a specific home address — documented as Trezor customers who had a device shipped to them. For 11,742 of them the list also has a phone number and an order number. That is not a password dump. It is a ready-made script for someone who wants to sound like Trezor, a courier, a bank or an exchange, and who already knows where you live and that you own this kind of device.
Trezor itself said this is the first time customer phone numbers and shipping addresses have been exposed in its history. It warned of more convincing phishing: fake emails, phone calls, letters, and people impersonating Trezor, banks or exchanges. Trezor said it has no confirmed cases of the data being misused so far. The copy that was taken still cannot be pulled back.
What to actually expect
- If you were in this breach, the genuine notice already came from [email withheld]. Trezor says that if you did not receive that email, you are not affected. A later message that offers to “check whether you were included,” “secure your device,” or confirm a delivery is using the news, not helping you.
- Expect contact that already knows something real — your name, your city or street, a recent order number, your phone number. That is what makes this different from ordinary junk mail. The dangerous messages will feel specific because they are.
- It will not only be email. Trezor specifically flagged calls and letters, and people pretending to be Trezor, a bank or an exchange. A voice that already has your address is harder to shrug off than a clumsy phishing email.
- If you are in the smaller group of 1,947, do not treat “only name, city and email” as a miss. That is still enough to write a convincing message, and Trezor has not finished confirming how far back those records go.
What you can and cannot fix
The records that were taken cannot be recalled. If your name, email, phone number or home address was sitting in ShipMonk’s systems, that copy is out. Trezor cannot delete it from whoever got in. You cannot either. An address, once tied to the fact that a Trezor was shipped there, stays tied.
What still helps, in this order:
- Treat unsolicited contact about this incident as hostile. Do not confirm an address, read back an order number, install anything, or discuss a recovery phrase or PIN with anyone who reached out to you. If you want Trezor’s own notice, type the company’s site into your browser yourself. Do not follow a link in a message.
- Tell the people who share your home. They are the ones who will pick up a phone or open a letter. They should know a stranger may already have your name and address, and that nobody needs a recovery phrase, a PIN, or “verification” of your order because of this incident.
- Shrink the rest of your public footprint. A bare shipping record becomes much more useful when it is joined to a people-search listing that already publishes relatives, extra phone numbers, an employer and previous addresses. Those listings, unlike the ShipMonk data, can actually be taken down. Removing them is the one part of this you can still change.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Was my home address leaked in the Trezor shipping data breach?
Trezor confirmed that a shipping partner, ShipMonk, exposed order data for about 13,689 customers af…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
Betterment Robo-Advisor 1.4M Customers — January 2026
Robo-advisor Betterment disclosed a breach affecting ~1.4 million customers in January 2026 via a fa…