Back to Blog
high severity · 4 min read Unverified claim — what this is

Was my home address leaked in the Trezor shipping data breach?

If you have an account with Was my home address, here’s what is being claimed, and what it would mean for you.

Trezor confirmed that a shipping partner, ShipMonk, exposed order data for about 13,689 customers after unauthorized access in August 2026. Most of those people had their name, email, phone number and home address taken. Trezor’s own devices and wallet keys were not involved.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Was my home address leaked in the Trezor shipping data breach?

On 13 August 2026, Trezor published an official notice and emailed customers from [email withheld]: its shipping partner ShipMonk had told the company on 10 August that someone had gained unauthorized access to systems holding customer order data.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

The incident covered orders sent to the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor keeps shipping data for 90 days, so most records were from about 10 May to 8 August 2026. About 13,689 customers were affected. Of those, 11,742 had the full set taken — full names, email addresses, phone numbers, shipping or home addresses, and order numbers. Another 1,947 had only names, cities and emails; Trezor said those records “may include older orders” and was still confirming dates with ShipMonk. Trezor’s own systems, devices, private keys and wallet backups were not compromised.

The keys are fine. That is not the problem.

Almost every report of this incident opened the same way: no wallets were broken into, no private keys were taken, your coins are not sitting in someone else’s account because of this leak. That is true. It is also the least useful part of the story if a Trezor was shipped to your home.

What the attacker actually holds is a list of named people, at known home addresses, documented as owning a hardware wallet. A hardware wallet is not a neutral purchase. It is a strong signal that someone keeps cryptocurrency. Add a phone number and an email, and that is enough to write a message that sounds like Trezor, to call you by name, or to decide which door is worth paying attention to. The coverage treated “keys safe” as reassurance. For a normal person, the live issue is the opposite: someone now has a short, accurate list of who bought one of these devices and where it was sent.

This is not a “your money is already gone” event. It is a “your name now sits next to your address and the fact that you own a hardware wallet” event. Those are different problems, and the second one does not end when the first is ruled out. There is no public list we can check to tell you whether your order was in this set. If you had a Trezor shipped to one of those countries in that window, treat the notice as if it applies until you have a reason not to. Trezor said it emailed the people it believes were affected.

What to actually expect

  • Emails or texts that mention this exact incident — a “replacement device,” a “security review,” or a link to “check if you were affected.” Trezor already sent the real notice from [email withheld]. It will not ask for your recovery words, PIN, or for you to plug your device into a website.
  • Calls or messages that use your real name, city, phone number or order number. Those fields were in the file. A stranger does not have to guess them.
  • A higher chance of targeted physical attention if you were in the group of 11,742 with a full address — someone watching for packages, or treating that house as a place that might hold a device. That is not the common outcome. It is the reason a list like this has value.
  • The same records showing up again later, sold or copied, with no second email from Trezor. Once a shipping file is taken, it is usually reused quietly.

What you can and cannot fix

If your name, email, phone number or home address was in this file, it is out. It cannot be recalled. Trezor cannot delete it from whoever took it. ShipMonk cannot either. Anyone offering to wipe you from the breach is selling something they cannot do.

What still helps, in order:

  • Treat any unexpected Trezor contact as fake unless you started it. Do not click links in mail about this leak. Do not read out recovery words, a PIN, or a “verification code” to anyone who reaches you. If you need the company, type the official site yourself.
  • Be slower than usual with the inbox and phone number that were on the order. Password-reset mail, “your package couldn’t be delivered,” and “confirm your order” texts are the easy next step with this kind of file. That traffic will look personal, because the sender already has the personal parts.
  • Shrink the rest of your public footprint. A bare shipping record becomes dangerous when it is joined to people-search listings that already publish relatives, extra phone numbers, employers and previous addresses. Those listings, unlike the leaked data, can actually be removed. Taking them down is the one step that makes the stolen file less useful to someone trying to build a full picture of you.
  • Assume a stranger now has a reason to care what arrives at that address. The leak does not reveal a wallet backup. It does show that a Trezor was sent there. If you keep a written copy of your recovery words in the same place, moving that paper is one of the few physical steps that still means something.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Was my home address is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed
Last reviewed August 8, 2026
Affected Unconfirmed
Data exposed Full namesEmail addressesPhone numbersHome addressesOrder numbersCities
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email