ShipMonk A.I CyberSecurity Scoring
ShipMonk
Company Information
Website:https://www.shipmonk.com
Employees number:1,300
Number of followers:26,263
NAICS:47
Industry Type:Transportation, Logistics, Supply Chain and Storage
Homepage:shipmonk.com
ShipMonk Risk Score (AI oriented)
Between 650 and 699
ShipMonkTransportation, Logistics, Supply Chain and Storage
Updated:
13/08/2026
13/08/2026
689/1000
Weak
B
ShipMonk Global Score (TPRM)
xxxx
ShipMonkTransportation, Logistics, Supply Chain and Storage
Score locked

ShipMonkWeak
Current Score
689B (WEAK)
01000
2 incidents
-61.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
634
AUGUST 2026
689
Breach
16 Aug 2026 • ShipMonk
SafePal: Safepal security vulnerability exposes data of 39,798 customers
SafePal Data Breach Exposing Customer Personal Information
633
CRITICAL-56
SAF1786970142
SafePal Discloses Data Breach Exposing Customer Personal Information
SafePal, a provider of crypto hardware wallets and security solutions, has reported a security incident that exposed the personal data of thousands of customers. The breach, disclosed on Sunday, involved an "authorization flaw" in a plug-in used to track customer orders, allowing unauthorized access to sensitive information.
The exposed data included names, physical addresses, and contact details, increasing the risk of phishing and impersonation attacks for affected users. However, SafePal confirmed that no cryptocurrency funds, passwords, or private wallet keys were compromised in the incident.
The vulnerability stemmed from a flaw in the order-tracking system, which functioned similarly to a retail receipt lookup where altering an order number could reveal another customer’s delivery details. SafePal has not disclosed the exact number of impacted users.
This breach follows a recent high-profile attack on Coldcard hardware wallets, where attackers reportedly stole at least $120 million in Bitcoin. While these incidents do not indicate a systemic flaw in hardware wallets, they underscore the persistent risks in crypto storage solutions and the importance of risk assessment in asset management.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
756
Breach
13 Aug 2026 • ShipMonk
Trezor and ShipMonk: Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers
Trezor Customers Face Phishing Risks After Third-Party Logistics Breach
689
CRITICAL-67
TRESHI1786631044
Trezor Customers Face Phishing Risks After Third-Party Logistics Breach
On August 10, 2026, hardware wallet manufacturer Trezor disclosed a data breach involving ShipMonk, one of its shipping providers, exposing personal details of thousands of customers. While Trezor’s own systems and devices remained uncompromised, the incident heightened phishing risks for affected users.
The breach impacted 13,689 customers who placed orders between May 10 and August 8, 2026, across the U.S., U.K., Sweden, Colombia, Brazil, Italy, and Portugal. Of these, 11,742 customers had full exposure of names, email addresses, phone numbers, and shipping addresses, while 1,947 had partial exposure limited to names, cities, and emails. Trezor’s 90-day data retention policy limited the scope, as older records were no longer stored by ShipMonk.
ShipMonk, which handles storage and shipping for Trezor, held the exposed data including names, emails, order numbers, phone numbers, and shipping addresses only as required for delivery. Trezor confirmed that no wallet security or firmware was affected, but the leaked details could be weaponized for phishing, spoofed calls, or fraudulent messages impersonating Trezor or financial services.
This marks the first time since Trezor’s 2013 founding that customer phone numbers and shipping addresses have been exposed in a breach. The company has notified affected users via [email protected] and urged caution against unsolicited requests for personal or wallet recovery information.
Trezor is working with ShipMonk to investigate and secure the affected systems. To mitigate future risks, the company plans to introduce an "Anonymous Delivery" option by September 2026 (EU) and end of 2026 (U.S.), featuring neutral packaging, locker pickup, and automatic deletion of shipping identifiers. Operations remain unaffected, and Trezor continues direct customer outreach.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
756
JUNE 2026
756
MAY 2026
756
APRIL 2026
756
MARCH 2026
756
FEBRUARY 2026
756
JANUARY 2026
756
DECEMBER 2025
756
NOVEMBER 2025
756
OCTOBER 2025
756
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ShipMonk ??
What was ShipMonk's A.I Rankiteo Cyber Score in August 2026 ??
What was ShipMonk's A.I Rankiteo Cyber Score in July 2026 ??
What was ShipMonk's A.I Rankiteo Cyber Score in June 2026 ??
What was ShipMonk's A.I Rankiteo Cyber Score in May 2026 ??
What was ShipMonk's A.I Rankiteo Cyber Score in April 2026 ??
What was ShipMonk's A.I Rankiteo Cyber Score in March 2026 ??
What was ShipMonk's A.I Rankiteo Cyber Score in February 2026 ??
What was ShipMonk's A.I Rankiteo Cyber Score in January 2026 ??
What was ShipMonk's A.I Rankiteo Cyber Score in December 2025 ??
What was ShipMonk's A.I Rankiteo Cyber Score in November 2025 ??
What was ShipMonk's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on ShipMonk's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ShipMonk ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ShipMonk's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?