The week of 7β13 August produced an unusually clean illustration of the dominant breach pattern of 2026. Five significant incidents. In four of them, the company that notified you was not the company that got hacked.
The ledger
Framework β the modular, repairable laptop maker β told all of its customers that attackers accessed names, email addresses, phone numbers, and physical addresses. Disclosed 7 August. The intrusion was at a third-party business intelligence vendor.
Trezor β the hardware wallet manufacturer β disclosed a breach affecting nearly 14,000 customers who received orders between 10 May and 8 August 2026. Exposed: names, shipping addresses, email addresses, phone numbers, across the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. The intrusion was at ShipMonk, its shipping and logistics provider.
Ceva Logistics β a global freight and contract logistics operator β leaked names, home addresses, phone numbers, and email addresses belonging to customers of Bol, De Bijenkorf, Ajax FC, ING, Ace & Tate, and Valve. One vendor compromise, and the fallout lands on a bank, a football club, a department store, an eyewear brand, and Steam users at once.
Wesco β supply chain and distribution β 2.6 million records claimed by the group ExfilSquad, including customer and employee PII, CRM profiles, and authentication metadata.
Unlimited Technology Systems β healthcare software β 3.8 million people, from an incident in October 2025, notified 1 July 2026. Exposed: full names, Social Security numbers, dates of birth, addresses, phone numbers, driverβs licence scans, insurance cards, intake forms, policy numbers, medical record numbers, dates of service, and diagnosis information.
The Framework and Trezor problem is specific
Most breach coverage treats customer lists as low-severity. Names and addresses, no passwords, no card numbers β a shrug.
That analysis fails badly for these two companies, because who their customers are is itself the sensitive fact.
Trezor sells hardware cryptocurrency wallets. A list of 14,000 verified names and home addresses of people who recently purchased a device whose entire purpose is storing bearer assets is not a marketing list. It is a target list, and it has a well-documented use: the β$5 wrench attackβ, in which the holder is physically coerced into surrendering their keys. Violent home-invasion robberies of crypto holders have risen sharply, and the limiting factor for attackers has always been identifying who holds significant assets at which address. This breach supplies exactly that, geographically sorted across seven countries. It also supplies the ingredients for the standard follow-on scam: a convincing βyour Trezor is compromised, enter your seed phraseβ email to a verified recent buyer.
Trezor had already been through a version of this in 2022, via a compromised newsletter vendor. The lesson available then was the same one available now.
Framework sells laptops to people who selected them for repairability, control, and privacy. Its customer list skews toward Linux users, security researchers, and journalists β people whose home address being in a stolen database carries above-average consequence.
In both cases, customers paid a premium to a company aligned with their threat model, and were exposed by a business intelligence platform and a fulfilment provider they never chose, never evaluated, and in most cases could not have named.
The vendor is the perimeter
The structural point is simple and keeps not being acted on.
Your data does not live where you gave it. It lives in the BI platform the company uses to analyse orders, the 3PL that picks and ships them, the CRM that stores the support conversation, the email service provider that sends the receipt, the analytics that measured the checkout, and the freight forwarder that moved the pallet. Every one of those is a copy, on infrastructure with different security, different logging, and different incentives.
Ceva makes the amplification obvious. Ceva has no consumer relationship with anyone. Its customers are companies. Breach Ceva once and you harvest the end customers of a bank, a retailer, a football club, and a games platform in a single action. Attackers understand this arithmetic better than procurement departments do.
And the disclosure chain runs backwards. Ceva knows first. The brands find out second. You find out fourth, if at all, and the notification arrives from a company you do business with about a company you have never heard of.
The healthcare outlier
Unlimited Technology Systems is a different failure. The breach occurred in October 2025. Notification came 1 July 2026 β roughly eight months later. HIPAAβs breach notification rule requires notice without unreasonable delay and no later than 60 days from discovery.
The content is maximal: SSNs, government ID scans, insurance details, medical record numbers, and diagnoses. That combination supports medical identity theft, insurance fraud, tax fraud, and targeted extortion, and unlike a card number, none of it can be reissued. Eight months is eight months during which 3.8 million people took no protective action because they did not know they needed to.
What it means in practice
Choosing a privacy-respecting company does not get you a privacy-respecting supply chain. Framework and Trezor are among the most privacy-aligned vendors in consumer hardware. It did not help, because the failure was two companies downstream.
βJust names and addressesβ depends entirely on the list. The severity of a customer list is a function of what membership in it reveals. For a hardware wallet vendor, it reveals wealth and location.
One vendor breach is now N brand breaches. Concentration in logistics, fulfilment, and BI tooling means the blast radius of a single compromise is measured in companies, not records.
Delayed notification is its own harm. The October-to-July gap did more damage to those 3.8 million people than several of the other incidents combined.
What you can do
-
Trezor buyers: nothing about your funds is at risk, and no legitimate party will ever ask for your recovery seed. Not Trezor, not support, not a firmware update, not an email about this breach. If asked, it is fraud, full stop.
-
If you bought a hardware wallet and your address is out, treat it as a physical security matter. Consider a passphrase-protected hidden wallet, and consider not discussing holdings anywhere your name is attached.
-
Ship to a locker, a pickup point, or a mailbox service for sensitive purchases. Your home address is the hardest identifier to change and the one every fulfilment vendor holds.
-
Use per-vendor email aliases. When a breach surfaces, the alias tells you immediately which relationship leaked, and you can burn it without changing your primary address.
-
Anyone in the Unlimited Technology Systems cohort: freeze your credit at all three bureaus now, and request an IRS Identity Protection PIN. SSN plus ID scan plus diagnosis data is the full medical identity theft kit, and monitoring only tells you after it has been used. See the wider 2026 breach pattern for how routine this has become.



