< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

3 clusters · 19 sources · 28 days · First seen · Last updated

Trezor customer data breach and phishing attacks

Overview

Hardware wallet manufacturer Trezor confirmed a data breach involving its shipping and fulfillment partner, ShipMonk. Initially, Trezor reported that an unauthorized actor accessed systems containing order records for approximately 13,689 customers across seven countries, including the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. The breach targeted orders placed between May 10 and August 8, 2026, exposing names, physical addresses, phone numbers, and email addresses. Trezor stated that its internal infrastructure, hardware wallets, private keys, and backup systems were not compromised. To mitigate future risks, the company announced plans for an ‘Anonymous Delivery’ option to be launched in the EU and US later in 2026.

By September 2026, the scale of the breach expanded significantly to over 80,000 affected users after it was discovered that ShipMonk had failed to delete historical order data from 2019 to 2021.

In early September 2026, Trezor also warned of a sophisticated phishing campaign following a security breach at its third-party email service provider, Brevo. Attackers exploited flaws in Brevo’s login and single sign-on (SSO) configurations to gain access to client accounts and distribute fraudulent emails from Trezor’s legitimate domain. Titled ‘Critical Security Alert: STM32 Entropy Vulnerability’, these messages falsely claimed a hardware-level defect in microcontrollers could compromise recovery phrases, attempting to trick users into downloading malicious software to reveal seed phrases. Approximately 347,000 Trezor newsletter subscribers were targeted, with an estimated 2,500 users clicking the malicious link. Other firms using Brevo, such as BitBox and CoinTracking, also reported unauthorized activity. Trezor maintains that its hardware, software, and private keys remain secure.

Entities

Trezor · ShipMonk · Nick Neuman · BitBox · United States

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 2 days ago

    [TECHNOLOGY] 18 sources
    Trezor warns of phishing campaign following Brevo email provider breach

    A breach at email provider Brevo allowed hackers to send phishing emails from Trezor’s legitimate domain, targeting 347,000 subscribers with fake security alerts regarding STM32 hardware vulnerabilities.

  2. 5 days ago

    [TECHNOLOGY] 4 sources
    Trezor data breach expands to over 80,000 customers

    Trezor reports its data breach has expanded to over 80,000 users after shipping vendor ShipMonk failed to delete historical customer records as requested.

  3. 29 days ago

    [TECHNOLOGY] 32 sources
    Trezor customer data exposed in ShipMonk shipping breach

    A data breach at Trezor's shipping partner ShipMonk has exposed the personal details of 13,689 customers, increasing phishing risks despite Trezor's core systems remaining secure.

Sources

bitcoinbasis.de · bitcoinethereumnews.com · bitnewsbot.com · btc-echo.de · cahighways.org · cointelegraph.com · criptotendencias.com · cryptoast.fr · cryptobreaking.com · cryptopolitan.com · decrypt.co · detlionblood32.wordpress.com · it-boltwise.de · mycryptoparadise.com · neweconomy.jp · news.trijo.co · primanews.org · spacemoney.com.br · u.today

This summary has been updated 3 times: see revision history