Trezor Says ShipMonk Breach Exposed Order Data for 13,689 Customers: 21 outlets compared – NewsCord

Data breach at ShipMonk exposed personal data for 13,689 Trezor customers. Exposed data included full names, shipping addresses, email addresses, and phone numbers.
Beat 1 · The verdict
Whether the article mentions the breach’s underlying cause (Metabase zero-day SQLi)
Beat 2 · The divide, quote v quote
“attackers exploited a vulnerability in the third-party analytics platform Metabase”
“its third-party fulfillment partner, ShipMonk, had experienced “unauthorized access””
Read them yourself
Do not take our word for it. Here is what they published.
Keep the thread
Instagram Unveils Redesigned Wordmark After A Decade, Replacing Cursive Typeface
how 14 outlets framed it →
Millions Watch Europe’s First Solar Eclipse In 27 Years From Iceland To Spain
how 17 outlets framed it →
Hardware wallet maker Trezor disclosed that a breach at its fulfillment partner ShipMonk exposed order data for 13,689 customers, with the company saying the incident affected customers who received orders 90 days prior to August 8.
“13,689 customers”
Trezor said 11,742 customers had their names, emails, phone numbers, and shipping addresses leaked, while another 1,947 customers had just their names, cities and emails exposed.
In a Thursday post, Trezor said, "On Monday, August 10, 2026, one of our shipping providers, ShipMonk, informed us of unauthorized access to their systems containing customer data," and it added that its operations or services were not impacted.
BleepingComputer reported that the breach affected customers from the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th, 2026.
Trezor also warned that affected customers "could experience an increase in phishing attempts" even though it said its systems and devices remain secure.
Trezor told customers to treat unexpected contact with suspicion and warned that scammers can use leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor.
In its disclosure, Trezor emphasized, "To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts," and it said it is continuing to investigate the incident.
BleepingComputer reported that ShipMonk told customers the attackers exploited a vulnerability in the third-party analytics platform Metabase, and that Metabase had patched the vulnerability and invalidated all active sessions.
The breach comes after other Trezor-related incidents, including a January 2024 disclosure that 66,000 users who interacted with Trezor Support since December 2021 may have had their names, usernames, and email addresses exposed.
Bitcoin Magazine also pointed to a broader pattern, noting that in 2020 an unauthorized party accessed Ledger’s e-commerce and marketing database, leaking over 1 million email addresses and the personal contact data of nearly 10,000 customers.
Trezor said the scope was limited by a policy requiring partners to delete or anonymize order data 90 days after delivery, which it said meant older orders were no longer held in ShipMonk’s systems.
“delete or anonymize order data 90 days after delivery”
Decrypt reported that Trezor attributed the limited scope to a policy requiring partners to delete or anonymize order data 90 days after delivery, and it said customers who did not receive a notification email are not affected.
Trezor also announced an Anonymous Delivery option, with ForkLog saying it would allow customers to pick up devices from lockers, receive packages in plain packaging, and ensure delivery data is not retained.
ForkLog added that the service is expected to launch in the EU by September and in the US by the end of the year, while Trezor continued to investigate the breach.
CoinDesk reported that Trezor told it it has no confirmed cases of the exposed data being published, shared, or offered for sale yet, and that it is unaware of any scam or hack attempt linked to the incident so far.
Story read · 21 outlets · 3 disagreements · 1 fact unevenly covered
Keep reading
Nvidia Partners With Apollo, BlackRock, Blackstone, Goldman Sachs, KKR for Up to $500B AI Data Centers
how 11 outlets framed it →
TeamPCP Publishes Malicious LiteLLM Releases After Trivy Compromise, Exposing 2,488 Corporate Domains
11 sources compared →
DR Congo Ebola Outbreak Reaches Sixth Province After Death in Bas-Uele
16 sources compared →
Whether the article mentions the breach’s underlying cause (Metabase zero-day SQLi)
“attackers exploited a vulnerability in the third-party analytics platform Metabase”
“its third-party fulfillment partner, ShipMonk, had experienced “unauthorized access””
Some outlets add root-cause detail; others stop at partner compromise.
Coverage map
Western Alternative (14)
Other (6)
Western Mainstream (1)
Every outlet we compared, the headline it ran, and a link to the original article.
Trezor warns 14,000 customers after fulfilment partner suffers data breach
13 August, 2026
Trezor shipping partner breach exposes data of 13,689 customers
13 August, 2026
Trezor Data Breach Exposes 13,689 Customer Addresses
13 August, 2026
Data Breach At Trezor Leaks Info On Nearly 14,000 Bitcoin Wallet Users
13 August, 2026
A third-party security breach exposes the shipping addresses of 14,000 Trezor buyers.
13 August, 2026
Trezor reports data from 14K users exposed through shipping provider
13 August, 2026
Trezor discloses data breach affecting 13,689 customers
13 August, 2026
Trezor Provider ShipMonk Breach Exposed Order Data for 13,689 Hardware Wallet Customers
13 August, 2026
Trezor Customer Data Exposed in Shipping Partner Breach
13 August, 2026
Trezor Breach Exposes 13,700 Customers' Personal Data
13 August, 2026
Trezor Reports Data Breach Affecting Nearly 14,000 Customers
13 August, 2026
Trezor says 13,689 customers hit by data breach at shipping partner
13 August, 2026
Trezor reports data from 14K users exposed through shipping provider
13 August, 2026
"Trezor" warns 13,689 customers of an advanced phishing wave after shipping partner breach
13 August, 2026
Trezor Warns of Phishing Risk After 13,689 Customers' Data Exposed: What Happened?
13 August, 2026
Trezor discloses data breach affecting nearly 14,000 customers
13 August, 2026
Trezor: Customer Data Exposed in Shipping Breach
13 August, 2026
Breaking: Trezor says ShipMonk breach exposed data of 13,689 customers
13 August, 2026
Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers
13 August, 2026
Trezor Says Shipping Breach Exposed 13,689 Customers
13 August, 2026
Trezor Issues Urgent Data Breach Warning, Says Wallets Remain Secure
13 August, 2026
NewsCord Digest
Get every Technology and Science story like this one, in one email
Daily or weekly, only the topics you follow, each with the difference our analysis found across the outlets covering it.
Nvidia Partners With Apollo, BlackRock, Blackstone, Goldman Sachs, KKR for Up to $500B AI Data Centers
11 sources compared
TeamPCP Publishes Malicious LiteLLM Releases After Trivy Compromise, Exposing 2,488 Corporate Domains
11 sources compared
DR Congo Ebola Outbreak Reaches Sixth Province After Death in Bas-Uele
16 sources compared
Instagram Unveils Redesigned Wordmark After A Decade, Replacing Cursive Typeface
14 sources compared
Compare news sources. Expose media bias.
© 2026 NewsCord

source
This is a newsfeed from leading technology publications. No additional editorial review has been performed before posting.

Leave a Reply