Security News

Trezor Warns 14,000 Customers After Data Breach at Shipping Partner ShipMonk

Security Week · 14 Aug 2026
Key Takeaway Regularly review the security practices of third-party vendors and partners who handle your customer data, since their breaches can become your problem too.

Hardware cryptocurrency wallet maker Trezor has notified around 14,000 customers that their personal information was exposed in a data breach at ShipMonk, a third-party logistics provider used to fulfil shipping orders. The stolen data includes names, addresses, email addresses, and phone numbers.

While no financial or wallet credentials appear to have been compromised, the exposed contact details could still be used by attackers to launch convincing phishing or scam campaigns targeting Trezor customers, particularly given the high value often associated with cryptocurrency holders.

This incident highlights a growing risk for small and medium businesses: even when your own systems are secure, a breach at a third-party vendor or logistics partner can expose your customers' data and damage trust in your brand.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.