< Back to situation

[REVISION HISTORY]

Trezor customer data breach and phishing attacks

Updated 3 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-10 08:04 UTC → 2026-09-11 06:26 UTC · added removed

Hardware wallet manufacturer Trezor confirmed a data breach involving its shipping and fulfillment partner, ShipMonk. Initially, Trezor reported that an unauthorized actor accessed systems containing order records for approximately 13,689 customers across seven countries, including the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. The breach targeted orders placed between May 10 and August 8, 2026, exposing names, physical addresses, phone numbers, and email addresses. Trezor stated that its internal infrastructure, hardware wallets, private keys, and backup systems were not compromised. To mitigate future risks, the company announced plans for an ‘Anonymous Delivery’ option to be launched in the EU and US later in 2026. By September 2026, the scale of the breach expanded significantly to over 80,000 affected users. This increase occurred users after it was discovered that ShipMonk had failed to delete historical order data as requested, despite providing written confirmation of its removal. Consequently, records from orders placed between November 2019 and August 2021 were exposed, affecting an additional 67,000 customers in the United States. Trezor continues to warn users of increased risks regarding phishing, scams, and physical security. 2021. In early September 2026, Trezor also warned of a sophisticated phishing campaign following a security breach of at its third-party email provider. service provider, Brevo. Attackers used the provider exploited flaws in Brevo’s login and single sign-on (SSO) configurations to gain access to client accounts and distribute fraudulent emails titled from Trezor’s legitimate domain. Titled ‘Critical Security Alert: STM32 Entropy Vulnerability’, which these messages falsely claimed a hardware-level flaw defect in microcontrollers could weaken compromise recovery phrases, attempting to trick users into downloading malicious software to reveal seed phrases. Approximately 347,000 Trezor has taken down the domain used in the attack and is investigating how hackers accessed its legitimate domain. On September 9, 2026, it was noted that BitBox also issued warnings following a similar breach of a shared newsletter provider. The campaign targeted subscribers were targeted, with an estimated 2,500 users clicking the ‘human trust layer’ by malicious link. Other firms using compromised infrastructure to send emails Brevo, such as BitBox and CoinTracking, also reported unauthorized activity. Trezor maintains that passed standard security checks like SPF, DKIM, its hardware, software, and DMARC. private keys remain secure.

Versions

  1. 2026-09-11 06:26 UTC Trezor customer data breach and phishing attacks
  2. 2026-09-10 08:04 UTC Trezor customer data breach and phishing attacks
  3. 2026-09-10 00:06 UTC Trezor customer data breach and phishing attacks
  4. 2026-09-06 20:22 UTC Trezor customer data breach via ShipMonk

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.