Tech Trezor Alerts 14,000 Users Following Data Breach at Partner Company

This incident represents the first exposure of Trezor customers' shipping addresses.

By Olivier Acuna| Edited by Cheyenne Ligon 49 min ago 3 min read Make preferred on

Summary:

  • Trezor disclosed that nearly 14,000 customers had their personal information compromised due to a data breach at its fulfillment partner, ShipMonk, although Trezor's own systems and wallets are secure.
  • This breach, marking the first time Trezor has exposed customer phone numbers and shipping details, raises concerns about potential phishing and scams, even though no confirmed misuse of the leaked information has been reported.
  • The incident highlights a surge in global data breaches and follows prior incidents affecting Trezor and its competitor, Ledger, which have led to ongoing phishing and extortion scams.

According to Trezor, its fulfillment partner ShipMonk suffered unauthorized access to its systems, impacting the data of nearly 14,000 customers. The cold storage crypto wallet company revealed that the names, email addresses, phone numbers, and shipping addresses of 11,742 customers were compromised. Additionally, the names, cities, and email addresses of another 1,947 customers were also affected, totaling approximately 14,000 individuals across the U.S., the UK, Sweden, Colombia, Brazil, Italy, and Portugal.

In a statement on X, Trezor stated, "We have some difficult news to share. Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data."

This breach occurs amid a record number of global data breaches, as reported by SentinelOne, a U.S. cybersecurity firm. They noted a 17% increase in data breaches this year compared to 2025, with an average of 2,090 attacks happening worldwide each week. Furthermore, global data breaches have reportedly been increasing by 3% each month since January.

Trezor has informed all affected customers via email, assuring that those who did not receive a notification were not impacted. The company also told CoinDesk that it has no confirmed reports of the exposed data being sold, shared, or published. Additionally, customers who made purchases through Amazon are not affected, as those orders are processed by a different partner.

Trezor emphasized that its own systems remain uncompromised, and the crypto wallet devices are secure. However, there is an increased risk that affected customers may be targeted for phishing attempts through email, phone calls, or postal mail. Scammers could exploit the leaked information to impersonate banks, cryptocurrency exchanges, or even Trezor itself.

Individuals whose data has been compromised in a breach often remain vulnerable for years. Once logistics records are sold or made public, criminals frequently reuse this information for new scams. Extortionists have previously demanded ransoms of $700 to $1,000 by leveraging home addresses and sending counterfeit devices to victims. The costs associated with managing the legal, remediation, and reputational fallout from significant data leaks for hardware firms are estimated to exceed $33 million.

Moreover, crypto holders face an increasing threat of physical attacks. Reports indicate that in-person coercion attacks have resulted in losses totaling $124 million in the first half of this year, although not all incidents can be traced back to data breaches, according to Certik. The cybersecurity firm DeepStrike estimates that the financial losses due to data breaches reach the tens of billions of dollars annually.

Trezor noted that this breach is the first in its 13-year history to expose customer phone numbers and shipping addresses. However, Satoshi Labs, the parent company of Trezor, had previously reported a security breach in January 2024 affecting a third-party support portal, impacting 66,000 individuals. Additionally, another incident in April 2022 compromised the data of 106,856 Trezor customers. Notably, Trezor’s internal firmware and on-device cryptography have never been breached to facilitate the theft of funds.

In a similar context, Ledger, another prominent hardware wallet manufacturer, suffered a data breach in January, linked to its third-party e-commerce partner, Global-e. Ledger also experienced a significant breach in 2020 affecting nearly 300,000 users, leading to subsequent phishing campaigns where scammers sent fake Ledger devices to victims of the breach.

Data BreachesLedgerLatest Crypto News