Advertisement

Trezor Warns Thousands of Users After Third-Party Data Breach

Trezor has notified nearly 14,000 customers that their personal information was exposed after its fulfillment provider, ShipMonk, suffered unauthorized access to its systems.

The company said the incident is the first in Trezor’s history to expose customer shipping addresses.

The breach affected the names, email addresses, phone numbers and shipping addresses of 11,742 customers. Information from an additional 1,947 customers, including their names, cities and email addresses, was also exposed. The affected users are located in the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal.

Trezor disclosed the incident Thursday, saying one of its shipping partners had experienced a security breach involving sensitive order information.

The breach comes as cyberattacks and data exposures continue to increase worldwide. Cybersecurity firm SentinelOne said data breaches have risen 17% compared with 2025, with an average of 2,090 incidents reported globally each week. The number of breaches has also been growing by roughly 3% each month since January.

Trezor said it has emailed all customers whose information was affected and confirmed that anyone who did not receive a notification was not impacted. The company told CoinDesk that it has found no evidence so far that the exposed information has been published, distributed or sold.

Trezor also said it has not identified any scams or hacking attempts connected to the incident. Customers who purchased devices through Amazon were unaffected because those orders are processed through a separate fulfillment partner.

Crypto Funds and Devices Remain Safe

Trezor stressed that its internal systems were not compromised and that its hardware wallets remain secure. The company said customer funds were not directly exposed by the breach.

The primary concern is the increased risk of targeted social-engineering attacks. Criminals could use leaked names, contact details and addresses to impersonate Trezor, banks or cryptocurrency exchanges and contact victims through email, phone calls or physical mail.

Stolen customer information can remain valuable to attackers long after an initial breach. Data from shipping and logistics databases can be reused in future phishing campaigns, fraud attempts and other scams.

Criminals have previously used leaked home addresses to demand ransoms ranging from $700 to $1,000 or send fake hardware devices directly to victims. Companies can also face significant legal, recovery and reputational expenses after large-scale customer data leaks.

Physical security is becoming another concern for cryptocurrency holders. CertiK reported that crypto-related in-person coercion attacks totaled $124 million during the first half of the year, although the incidents were not necessarily linked to data breaches. DeepStrike estimates that data breaches result in tens of billions of dollars in losses globally each year.

Trezor Has Faced Earlier Third-Party Breaches

Trezor said the latest incident marks the first time in its 13-year history that customer phone numbers and shipping addresses have been exposed.

The company has experienced other third-party security incidents. Satoshi Labs, Trezor’s parent company, reported a breach involving an external support portal in January 2024 that affected 66,000 individuals. Another incident in April 2022 exposed information belonging to 106,856 Trezor customers.

Despite those incidents, Trezor said its internal firmware and on-device cryptographic security have never been remotely compromised to steal customer funds.

Other hardware wallet manufacturers have experienced similar breaches. Ledger reported a January incident involving its third-party e-commerce provider, Global-e. The company also suffered a major data breach in 2020 that exposed information belonging to nearly 300,000 users. In 2021, attackers used data from that breach in a follow-up phishing campaign involving counterfeit Ledger devices.