Personal data belonging to 13,689 Trezor customers was exposed in a breach at ShipMonk, the third-party fulfillment company responsible for shipping Trezor Shop orders across several markets.
Personal data belonging to 13,689 Trezor customers was exposed in a breach at ShipMonk, the third-party fulfillment company responsible for shipping Trezor Shop orders across several markets.
The August 13 disclosure covers customers who received orders in the U.S., U.K., Sweden, Colombia, Brazil, Italy or Portugal during the 90 days before August 8. ShipMonk notified Trezor of unauthorized access to systems containing customer information on August 10.
Names, Addresses And Phone Numbers Exposed
Full names, shipping addresses, phone numbers and email addresses were exposed for 11,742 customers. Another 1,947 customers had their names, cities and email addresses accessed.
Trezor systems, hardware wallets, private keys and wallet backups were not compromised. The exposed information instead gives scammers data that can be used to construct targeted emails, phone calls and physical correspondence impersonating Trezor, exchanges, banks or delivery companies.
A similar attack path previously led a Ledger user to lose about $1.07 million after receiving a fake support letterdirecting the victim to a phishing site that requested a recovery phrase.
Affected Trezor customers were contacted directly from [email protected]. Customers who did not receive the notification email are not included in the identified breach population.
90-Day Retention Policy Limits Breach Scope
Trezor requires purchase information to be deleted or anonymized 90 days after delivery, and ShipMonk operates under the same retention requirement.
Older customer records had therefore already been removed from the affected systems. Without that policy, the breach could have exposed shipping information accumulated across a much longer period rather than orders delivered since May 10.
The company plans to introduce an Anonymous Delivery option in the European Union by September and in the United States before the end of 2026. The system is expected to use locker collection, neutral packaging, generic sender information and automatic deletion of shipping identifiers after delivery.
Trezor Warns Customers Against Recovery-Phrase Requests
Trezor is asking affected customers to treat unexpected communications requesting immediate action or personal information as suspicious. A wallet backup should never be entered into a website or disclosed to anyone claiming to represent Trezor.
The breach arrives during a wider run of wallet-security incidents. Coldcard-linked drains became July’s largest crypto security loss, while a separate Ethereum whale was recently drained of $25.6 million through phishing after losing another $24.2 million from the same wallet in 2023.
ShipMonk has secured the affected systems while its investigation continues, and Trezor operations remain online. This is the first breach since Trezor was founded in 2013 to expose customer phone numbers and shipping addresses.
The post Trezor Says 13,689 Customers Exposed In ShipMonk Data Breach appeared first on Crypto Adventure.