Hands holding an open Trezor hardware wallet box with the device visible on a desk.
TECHNOLOGY

Trezor Warns 14,000 Customers of Data Breach at Shipping Partner

Image credit: Shutterstock

Key Takeaways

  • Nearly 14,000 Trezor customers had names, emails, phone numbers, and shipping addresses exposed after a breach at fulfillment partner ShipMonk.
  • Trezor said its own infrastructure and hardware wallets were not compromised, but warned affected customers face a heightened risk of phishing and impersonation scams.
  • This marks the first breach in Trezor’s history to expose phone numbers and shipping addresses, following prior incidents in 2022 and 2024 tied to other third parties.

Hardware wallet maker Trezor said nearly 14,000 customers had personal data exposed after its fulfillment partner, ShipMonk, suffered unauthorized access to its systems. The company said its own infrastructure and crypto wallet devices remain secure, but warned affected customers in seven countries they now face a heightened risk of phishing attempts.

What Data Was Exposed

Trezor said on Thursday that the breach compromised the names, email addresses, phone numbers and shipping addresses of 11,742 customers, plus the names, cities and email addresses of another 1,947 customers. In total, nearly 14,000 customers were affected across the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal.

“We have some difficult news to share.” 

Trezor said this in a post on X, adding that one of its shipping providers had experienced a breach exposing sensitive order data.

Trezor Says Its Wallets and Systems Remain Secure

Trezor said it notified all affected customers by email and confirmed that customers who did not receive that notice were not affected. The company said it has no confirmed cases of the exposed data being published, shared or offered for sale, and is not aware of any scam or hacking attempt linked to the incident so far. 

Customers who purchased Trezor devices through Amazon were not impacted, since those orders are fulfilled through a separate partner. Trezor emphasized that the breach did not compromise its own systems, and that its hardware wallets remain secure. 

The company described the risk to affected customers as indirect, warning that leaked contact and shipping information could let scammers impersonate banks, crypto exchanges or Trezor itself through email, phone or postal mail. 

Trezor said this marked the first breach in its 13-year history to expose customer phone numbers and shipping addresses.

The Long Tail Risk of a Fulfillment Breach

The incident lands amid a broader surge in data breaches globally. Cybersecurity firm SentinelOne reported that data breaches have risen 17% in 2026 compared with 2025, with an average of 2,090 attacks recorded worldwide each week, and said global breach activity has climbed roughly 3% month over month since January.

The risk from breaches like this one can persist well beyond the initial disclosure, based on patterns seen in prior hardware wallet breaches. Once stolen shipping and contact records are sold or published, cybercriminals can repurpose that data for scams for years afterward. 

In prior cases involving hardware wallet customers, extortionists have used leaked home addresses to demand ransoms of $700 to $1,000 and, in some instances, mailed counterfeit devices directly to victims.

Crypto holders have also faced a rising rate of physical, in-person coercion attacks, which totaled $124 million in losses during the first half of 2026 alone, according to blockchain security firm Certik, though not all of those cases can be traced to a specific data breach.

A Pattern Familiar to Hardware Wallet Makers

Trezor has faced smaller-scale breaches before. Its parent company, Satoshi Labs, reported a breach of a third-party support portal in January 2024 that affected roughly 66,000 people, and a separate 2022 incident tied to a third-party email marketing vendor compromised data belonging to more than 106,000 Trezor customers. 

The company said its internal firmware and on-device cryptography have never been remotely breached to steal funds.

Ledger, a rival hardware wallet maker, has faced a similar pattern of third-party breaches. Ledger disclosed a breach linked to its e-commerce partner Global-e in January, and a separate 2020 breach which affected nearly 300,000 users led to a follow-on scam campaign in which fraudsters mailed victims fake replacement devices.

More For You

Explore More News