Trezor customers are facing heightened phishing and security risks after a data breach at ShipMonk, one of the hardware wallet maker’s fulfillment partners, exposed personal information belonging to nearly 14,000 people.
Trezor said Thursday that 11,742 customers had their names, email addresses, phone numbers and shipping addresses compromised. Another 1,947 customers had their names, cities and email addresses exposed. The breach affected customers across the U.S., UK, Sweden, Colombia, Brazil, Italy and Portugal.
The crypto hardware wallet company said it notified affected customers by email. Those who did not receive a notification were not impacted. Trezor told CoinDesk that it had not identified any cases of the stolen data being published, shared or offered for sale, nor had it detected scams directly linked to the incident.
Trezor stressed that its own systems and hardware wallets were not compromised, meaning users’ crypto assets and device security remain unaffected. Amazon customers were also excluded from the breach because their orders are handled by another fulfillment provider.
However, leaked contact and shipping information could allow attackers to launch highly targeted phishing campaigns by impersonating Trezor, cryptocurrency exchanges, banks or other trusted organizations. Previous crypto data breaches have demonstrated that stolen addresses can also create longer-term physical security risks.
The incident comes amid a broader increase in cyberattacks. SentinelOne reported that global data breaches have risen 17% in 2026 compared with 2025, averaging around 2,090 attacks per week.
While Trezor described the ShipMonk incident as its first breach in 13 years exposing customer phone numbers and shipping addresses, its users have previously been affected by third-party security incidents. A support portal breach impacted about 66,000 people in 2024, while a Mailchimp compromise exposed data connected to more than 106,000 customers in 2022.
Rival hardware wallet maker Ledger has faced similar third-party breaches. A 2020 incident affected nearly 300,000 users and was later followed by scammers mailing counterfeit Ledger devices to some victims, highlighting how leaked customer data can remain a security threat years after the initial breach.
Comment 0