Trezor: ShipMonk shipping-provider breach exposes order PII
13 Aug 2026: Trezor disclosed that ShipMonk, a fulfillment partner, had unauthorized access to customer order data. About 11,742 buyers had full exposure (name, email, phone, shipping address) and 1,947 partial (name, city, email) — limited to recent orders in US, UK, Sweden, Colombia, Brazil, Italy, and Portugal within the 90 days before 8 Aug 2026. Trezor states its own systems, devices, private keys, and wallet backups were not compromised. Affected customers were emailed from @trezor.io; the real risk called out is more sophisticated phishing by mail, phone, or email. Confirmed via official Trezor blog + @Trezor post.
369 take: A hardware wallet can be fine and you can still get hunted — name, address, and phone from a shipper are enough for fake “support / firmware / delivery” plays. Never enter a seed or backup on a website or over the phone; only trust updates on official Trezor channels. Pulse lesson: treat any vendor or logistics PII leak as a phishing season for that cohort, not as proof the device itself was drained.