Trezor Data Breach: What UK Crypto Owners Should Do Now
By Simon Bumford, Founder · · 11 min read
Your Trezor was not hacked, but your name and home address may have been leaked. What the ShipMonk breach means for UK crypto owners, and what to do about it.
The short version
On 13 August 2026 Trezor confirmed that one of its shipping partners, a fulfilment company called ShipMonk, had been breached, exposing the order records of 13,689 customers, including customers in the UK. If you had a Trezor order delivered between 10 May and 8 August 2026, your name, home address, email address and phone number may now be in criminal hands. Here is what did not happen: your wallet was not hacked. No Trezor system, device, private key or recovery phrase was touched, because none of those things ever pass through a shipping database. Your keys are exactly as safe as they were last month. What has changed is who knows about you. A stranger may now know your name, where you live, and that you almost certainly own cryptocurrency. That combination invites a very predictable follow-up: convincing phishing emails, fake letters, bogus support calls and, rarely, worse. This article explains exactly what happened, how to tell if you are affected, and the specific steps that make the leaked data close to worthless, including the UK reporting routes most of the coverage leaves out.
What happened, and when
ShipMonk is one of the logistics companies Trezor uses to pack and post orders. On 10 August 2026, ShipMonk told Trezor that an unauthorised party had accessed ShipMonk systems containing Trezor customer order data. Trezor published its official disclosure three days later, on 13 August, and says it has contacted affected customers directly. The exposed records cover orders delivered between 10 May and 8 August 2026 across seven countries: the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor's disclosure names the UK explicitly, so British customers are not left guessing. The Register noted that some of the partially exposed orders may predate the May cut-off. One detail deserves credit: the window is only three months wide because Trezor requires fulfilment partners to delete or anonymise order data 90 days after delivery. That policy is the difference between 13,689 exposed customers and what happened to Ledger in 2020, when years of accumulated shop data leaked at once. BleepingComputer reported that ShipMonk's notification to those affected attributed the intrusion to a vulnerability in an analytics tool it used; ShipMonk had made no wider public statement when this article was last reviewed, so treat the root cause as provisional.
What was exposed, and what was not
The numbers from Trezor's own disclosure: 11,742 customers had their full name, email address, phone number and shipping address exposed, and a further 1,947 had a partial record exposed showing name, city and email address. Order numbers were included; the contents of parcels were not, though nobody needs a packing list to guess what a Trezor shipment contains. Just as important is what was not in the stolen data. Trezor states plainly that Trezor systems, hardware wallets, private keys and wallet backups were not affected. There is no indication that payment card details were involved, and no wallet passwords or PINs were exposed, because ShipMonk never held any of those things. The recovery phrase you wrote down at setup has never existed in any company's database, which is precisely why it is the one thing every scammer now has to ask you for.
How do I know if I am affected?
Three questions settle it. Did you order directly from Trezor's own shop? Was the order delivered between 10 May and 8 August 2026? Was it delivered in one of the seven countries listed above? If yes to all three, work on the assumption that your details leaked. Trezor says it has contacted affected customers, so check the inbox you used for the order, but verify anything you receive by going to trezor.io directly rather than clicking links in an email. Be especially careful with messages about the breach itself. Criminals routinely impersonate a company's incident response. After Trezor's January 2024 support portal incident, which exposed contact details of up to 66,000 support users, Trezor confirmed that dozens of those users were promptly targeted with fake support emails asking them to enter their recovery seed. A genuine breach notification will never ask you to verify, validate or re-enter anything. If you bought your device from a third-party reseller rather than Trezor's own shop, this particular leak does not include you, though everything below is still worth doing.
Why a name and address is enough to matter
The leaked file is not a treasure map. It cannot open a wallet. What it does is convert mass phishing into targeted phishing, which works far more often. An email that greets you by name, quotes a genuine order number and names the device you actually own sails past the mental filter that catches generic spam. Expect fake firmware updates, fake refund offers and fake urgent warnings that your device is affected, arriving by email, text, phone and post. After Ledger's 2020 leak, customers received waves of exactly this, including extortion emails, documented by researchers at Bitdefender, that quoted the victim's leaked record to appear credible. Trezor's own advice to affected customers is to expect exactly this pattern, and SafePal issued the same warning after its incident days later. There is also a physical dimension, and it deserves sober words rather than drama. Chainalysis, which tracks what the industry calls wrench attacks, documented a record $58 million stolen through physical attacks on crypto holders in 2025 and approximately $30 million in the first half of 2026, and notes that attackers pick targets from exposed information such as data breaches and social media. Roughly a quarter to three in ten of recent cases targeted a holder's family members or acquaintances rather than the holder. The UK is not exempt: in July 2025 two crypto investors were held for more than two days in a London flat and forced to transfer funds, a case that ended in convictions at Inner London Crown Court in August 2026. Such attacks remain rare, and no public evidence connects any specific attack to this specific leak. But a stranger knowing that a crypto owner lives at your address is exactly the raw material, which is why the checklist below includes your household, not just your inbox.
What to do now: a UK checklist
First, harden the assumption. Treat every unsolicited crypto-related message you receive from now on as hostile until proven otherwise, whether it arrives by email, text, phone or letter. Your recovery phrase never gets typed into a website, an app or a 'validation tool', and it is never read out on a phone call. Trezor will not ask for it. Nobody honest will. Second, use the free UK reporting routes, because every report helps take down the criminal's infrastructure. Forward phishing emails to report@phishing.gov.uk, the NCSC's Suspicious Email Reporting Service, and forward scam texts to 7726. If a scam has actually cost you money, contact your bank immediately, then report it to Report Fraud, the national service that replaced Action Fraud in December 2025, online or on 0300 123 2040. In Scotland, report to Police Scotland on 101. Third, upgrade the accounts the leak points at. The email address in the stolen file is the front door to everything else, so protect it first with passkeys, the NCSC's current recommendation, or an authenticator app rather than text-message codes. SIM swap fraud rose more than tenfold in the UK in 2024, and a hijacked phone number captures every code sent by text. Fourth, know your data rights. The ICO's guidance for people caught in a breach is practical: you can ask the organisation what was taken and what it is doing about it, and it should reply within one month. If you are worried about wider identity misuse, Cifas protective registration adds a warning flag to your credit file. And keep some perspective at home: brief the people you live with on what a fake Trezor letter or caller might sound like, and use a collection point or work address for future deliveries if you would rather they did not carry your home address. Trezor itself has said it plans an anonymous delivery option in the EU from September 2026. Finally, give yourself a tripwire. You cannot personally watch the blockchain all day, but a watch-only monitor can. Bitzo's Bitcoin Watchtower runs on our own UK node and emails you the moment coins move from an address you have asked it to watch, usually while the transaction is still waiting to confirm. If the worst ever happened, you would know in minutes rather than whenever you next checked.
Should I move my coins?
Nothing about this incident requires it. The breach exposed shipping records, not keys, and Trezor's own guidance focuses on phishing vigilance, not migration. More to the point, panic migration is the attack. The most dangerous email you could receive this month is one that looks like Trezor, tells you your wallet is compromised, and helpfully offers a migration tool or asks for your seed to move you to a 'secure wallet'. Acting calmly and unprompted is the entire game. If, knowing all that, you would simply sleep better on a fresh seed, that is a reasonable personal choice. Do it on your own initiative, on the device itself, with no website or support agent involved: set up the new wallet, back up the new phrase on paper or steel, send a small test amount, then move the rest. Our Trezor backup guide walks through the process. And if you do rotate wallets, update whatever your family or executor would one day rely on, because a recovery document pointing at an empty wallet fails at the worst possible moment.
The pattern: parcels leak, vaults hold
Zoom out and this is not really a Trezor story. Ledger's e-commerce database leaked in 2020, and approximately 272,000 customers' names, home addresses and phone numbers were dumped publicly that December. Trezor's newsletter list leaked through Mailchimp in 2022, and its support portal was breached in January 2024. Ledger customers were exposed again in January 2026 through Global-e, a third-party commerce provider. SafePal disclosed on 16 August 2026 that an order-tracking flaw had exposed around 39,800 customers. In every single case, the disclosure carries the same reassurance: devices, keys and funds were not affected. That consistency is the lesson. The cryptography keeps holding; the supply chain keeps leaking. Buying a hardware wallet under your own name at your own address creates a permanent record linking you to cryptocurrency, held by companies you will never think about again until one of them emails you an apology. You cannot delete those records, but you can decide how much they matter. A holder with disciplined seed hygiene, phishing-proof habits, a monitored wallet and a family who know the playbook has turned the leaked file into junk data. That, not the breach itself, is the part you control. Our guide to who can link you to your bitcoin maps the full trail, well beyond shipping databases, and our four layers of crypto risk framework shows where this kind of exposure sits among the risks that actually cost holders money.
After the breach: watching and continuity
Two longer-term actions turn this incident into a prompt for better security rather than a lingering worry. The first is monitoring. A leak like this raises the value of knowing immediately if coins ever move without you. The Watchtower from the checklist above is included with Bitzo's Continuity Plus plan for up to 3 addresses and with Private Client for up to 20: watch-only, no keys ever, and the addresses you enrol stay on Bitzo's own node rather than being pasted into public block explorers. The second is continuity. This breach is a reminder that being known to hold crypto has consequences, and one of them arrives on the day you are no longer here to manage it: bereaved families of known crypto holders are a soft target for exactly the impersonation and recovery scams this article describes. If your household knows the phishing playbook, knows what exists, and has a documented, verified route to recover it that never exposes your keys, you have closed both gaps at once. That is the planning Bitzo exists for. Take the free five-minute Bitcoin inheritance scorecard to see where your arrangements stand, or read how crypto inheritance planning works. Last reviewed 18 August 2026. This article describes the incident as disclosed at that date; check Trezor's official channels for any later updates.
Frequently Asked Questions
Was Trezor hacked?
No. The breach happened at ShipMonk, a third-party fulfilment company that ships Trezor orders. Trezor states that no Trezor system, hardware wallet, private key or wallet backup was affected. What leaked was order information: names, home addresses, email addresses and phone numbers for 11,742 customers, and partial records for 1,947 more.
Is my crypto safe after the Trezor data breach?
Yes, in the sense that matters: private keys and recovery phrases were never in the breached systems, so nobody can spend your coins using the leaked data. The real risk is deception. Criminals now have enough detail to send convincing personalised phishing, and every such scam ends with a request for your recovery phrase. Refuse that one request and the scam fails.
How do I know if I am affected?
You are potentially affected if you ordered directly from Trezor and the order was delivered between 10 May and 8 August 2026 in the US, UK, Sweden, Colombia, Brazil, Italy or Portugal. Trezor says it has contacted affected customers. Verify through trezor.io directly, and treat any unsolicited link inviting you to check whether you are affected as phishing.
Should I move my crypto to a new wallet?
The incident does not require it, because keys were not exposed. Never move funds because an email, call or pop-up told you to; that is the scam. If you independently prefer a fresh start, create the new wallet on the device itself, back up the new phrase offline, test with a small amount first, and update any recovery or inheritance documents that reference the old wallet.
Can criminals steal my bitcoin with just my name and address?
Not directly. Nothing in a shipping record can sign a transaction. The data is used for targeting: personalised phishing, fake support calls, fraudulent letters and, rarely, physical intimidation. Your defences are unchanged but matter more now: never reveal your recovery phrase, verify everything through official channels, and consider monitoring so any theft is spotted immediately.
How do I report a crypto phishing attempt in the UK?
Forward suspicious emails to report@phishing.gov.uk and scam texts to 7726, both free. If you have lost money, contact your bank first, then report to Report Fraud, which replaced Action Fraud in December 2025, at reportfraud.police.uk or on 0300 123 2040. In Scotland, report to Police Scotland on 101.
Can I claim compensation for a data breach in the UK?
You have rights under UK data protection law: you can ask the organisation what data of yours was involved, and you can complain to the ICO free of charge if you are unhappy with its response. The ICO itself cannot award compensation; that generally requires a claim against the organisation, so take independent advice before pursuing one. This article is general information, not legal advice.
Sources
- Trezor official disclosure: recent customer data exposed in shipping provider incident (13 Aug 2026)
- The Register: Trezor confirms 13,000 customers' details exposed in logistics breach (14 Aug 2026)
- BleepingComputer: Trezor discloses data breach affecting nearly 14,000 customers (13 Aug 2026)
- Ledger: message from Ledger's CEO on the 2020 data leak
- SafePal security update: order data incident (16 Aug 2026)
- Bitdefender: extortion campaign targeting Ledger leak victims (2021)
- Chainalysis research: violent wrench attacks on crypto holders (6 Aug 2026)
- NCSC: data breaches, guidance for individuals and families
- ICO: what steps should I take if I have experienced a data breach?
- Report Fraud (formerly Action Fraud): guide to reporting cyber crime and fraud
Ready to plan your crypto inheritance?
Speak to our UK-based team about your situation. No obligation, no pressure.
Speak to us