# Trezor customer data breach and phishing attacks

> Live situation record from CLSTR: https://clstr.news/situations/trezor-customer-data-breach-via-shipmonk
> Updated: 2026-09-09T21:36:33.000Z. Sources: 19. Developments: 3.

Hardware wallet manufacturer Trezor confirmed a data breach involving its shipping and fulfillment partner, ShipMonk. Initially, Trezor reported that an unauthorized actor accessed systems containing order records for approximately 13,689 customers across seven countries, including the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. The breach targeted orders placed between May 10 and August 8, 2026, exposing names, physical addresses, phone numbers, and email addresses. Trezor stated that its internal infrastructure, hardware wallets, private keys, and backup systems were not compromised. To mitigate future risks, the company announced plans for an ‘Anonymous Delivery’ option to be launched in the EU and US later in 2026. 

By September 2026, the scale of the breach expanded significantly to over 80,000 affected users after it was discovered that ShipMonk had failed to delete historical order data from 2019 to 2021. 

In early September 2026, Trezor also warned of a sophisticated phishing campaign following a security breach at its third-party email service provider, Brevo. Attackers exploited flaws in Brevo’s login and single sign-on (SSO) configurations to gain access to client accounts and distribute fraudulent emails from Trezor’s legitimate domain. Titled ‘Critical Security Alert: STM32 Entropy Vulnerability’, these messages falsely claimed a hardware-level defect in microcontrollers could compromise recovery phrases, attempting to trick users into downloading malicious software to reveal seed phrases. Approximately 347,000 Trezor newsletter subscribers were targeted, with an estimated 2,500 users clicking the malicious link. Other firms using Brevo, such as BitBox and CoinTracking, also reported unauthorized activity. Trezor maintains that its hardware, software, and private keys remain secure.

## Claims

- The phishing email used the subject line ‘Critical Security Alert: STM32 Entropy Vulnerability’. (corroborated by 12 sources)
- Trezor's third-party email provider was breached. (corroborated by 11 sources)
- No Trezor devices, software, or private keys were compromised in the breach. (corroborated by 5 sources)
- BitBox users also reported receiving phishing attempts linked to the same provider compromise. (corroborated by 5 sources)
- The email platform Brevo was breached, affecting approximately 347,000 Trezor newsletter subscribers. (corroborated by 4 sources)
- Approximately 2,500 users clicked the malicious link before the domain was taken down. (corroborated by 3 sources)
- The attacker exploited a flaw in Brevo's single sign-on (SSO) and authorization boundaries to access multiple client accounts. (corroborated by 3 sources)
- The phishing emails passed standard authentication checks including SPF, DKIM, and DMARC. (corroborated by 2 sources)

## Timeline

### 2026-09-09: Trezor warns of phishing campaign following Brevo email provider breach

A breach at email provider Brevo allowed hackers to send phishing emails from Trezor’s legitimate domain, targeting 347,000 subscribers with fake security alerts regarding STM32 hardware vulnerabilities.

18 sources. https://clstr.news/cluster/trezor-warns-of-phishing-attack-following-email-provider-breach

### 2026-09-06: Trezor data breach expands to over 80,000 customers

Trezor reports its data breach has expanded to over 80,000 users after shipping vendor ShipMonk failed to delete historical customer records as requested.

4 sources. https://clstr.news/cluster/trezor-data-breach-expands-to-over-80000-customers

### 2026-08-13: Trezor customer data exposed in ShipMonk shipping breach

A data breach at Trezor's shipping partner ShipMonk has exposed the personal details of 13,689 customers, increasing phishing risks despite Trezor's core systems remaining secure.

32 sources. https://clstr.news/cluster/trezor-reports-data-breach-at-shipping-provider-shipmonk

---
Cite as: Trezor customer data breach and phishing attacks. CLSTR, https://clstr.news/situations/trezor-customer-data-breach-via-shipmonk
