
Trezor notified 11,742 customers after a ShipMonk breach leaked names, addresses and phone numbers. The company said crypto assets and device security were not affected.
Alpha Score of 52 reflects moderate overall profile with strong momentum, weak value, moderate sentiment. Based on 3 of 4 signals – score is capped at 90 until remaining data ingests.
Trezor customers are facing a wave of phishing attempts after a data breach at ShipMonk, a fulfillment partner for the hardware wallet maker, exposed personal information tied to nearly 14,000 people.
The company said Thursday that 11,742 customers had their names, email addresses, phone numbers and shipping addresses compromised. Another 1,947 customers had their names, cities and email addresses exposed. The breach affected customers in the U.S., UK, Sweden, Colombia, Brazil, Italy and Portugal.
Trezor notified affected users by email, the company said. Those who did not get a notification were not impacted. Trezor told CoinDesk it had found no evidence the stolen data had been published, shared or offered for sale, and had not detected scams directly linked to the incident.
Trezor stressed that its own systems and hardware wallets were not compromised. Users' crypto assets and device security remain unaffected, the company said. Amazon customers were also excluded from the breach because those orders go through a different provider.
Still, leaked contact and shipping details give attackers the raw material for highly targeted phishing campaigns. Scammers can impersonate Trezor, crypto exchanges, banks or other trusted organizations using the exposed names and addresses. Previous crypto data breaches have shown that stolen physical addresses can create longer-term security risks.
The incident comes as cyberattacks rise globally. SentinelOne reported that data breaches have increased 17% in 2026 compared with 2025, averaging about 2,090 attacks per week.
While Trezor described the ShipMonk incident as its first breach in 13 years exposing phone numbers and shipping addresses, its users have been hit by third-party incidents before. A support portal breach affected about 66,000 people in 2024. A Mailchimp compromise exposed data tied to more than 106,000 customers in 2022.
Rival hardware wallet maker Ledger has faced similar third-party breaches. A 2020 incident affected nearly 300,000 users and was later followed by scammers mailing counterfeit Ledger devices to some victims. The episode showed how leaked customer data can remain a threat years after the initial breach.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.