
ShipMonk exposed 14,000 Trezor customers' names, addresses and phone numbers. Trezor's own systems were untouched, but phishing risk is high.
Alpha Score of 52 reflects moderate overall profile with strong momentum, weak value, moderate sentiment. Based on 3 of 4 signals – score is capped at 90 until remaining data ingests.
Hardware wallet maker Trezor told roughly 14,000 customers their personal data was stolen in a breach at ShipMonk, the logistics firm Trezor uses to fulfill orders.
The company disclosed the incident August 13. ShipMonk's systems were hit between May 10 and August 8, exposing full names, email addresses, phone numbers and shipping addresses for 11,742 customers, Trezor said. Another 1,947 people had partial information – name, city and email – compromised.
Affected buyers are in seven countries: the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal. Anyone who ordered through Amazon is fine; those shipments run through a different provider.
Trezor emailed every impacted customer directly. If you did not get one, your data is safe.
The company stressed that its own infrastructure was untouched. "Your Trezor device is secure," it said. The real risk is secondary: criminals can use the stolen details to impersonate Trezor, a bank, or a crypto exchange in phishing calls, emails, or even physical mail.
SentinelOne, a cybersecurity analytics firm, reported a 17% jump in breaches in 2026 versus last year, with roughly 2,090 cyberattacks a week globally. Stolen personal data often trades on darknet markets for months. Criminals have used home addresses to extort victims for sums between $700 and $1,000, and have shipped fake hardware wallets to targets, Trezor noted.
In-person coercion attacks on crypto holders are rising too. Certik, a blockchain security firm, tallied $124 million in losses from such attacks in the first half of 2026.
This is the first time in Trezor's 13-year history that phone numbers and physical addresses have leaked. A 2024 breach hit support-platform accounts; a 2022 one exposed email data. Neither included delivery details.
Trezor's firmware and device-level security have never been breached remotely, the company said.
Ledger, a rival hardware wallet maker, suffered a similar third-party data leak in January 2026 through its e-commerce vendor. A 2020 Ledger breach hit nearly 300,000 people and led to fraudsters mailing counterfeit devices to victims.
Trezor said that so far, none of the stolen data has appeared on public forums, been traded, or been used in any fraud.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.