Trezor shipping provider breach exposes personal data of nearly 14,000 customers

摘要:A breach at Trezors shipping partner ShipMonk exposed personal data of roughly 13,700 customers, including 11,742 users whose names, email addresses, phone numbers, and shipping addresses were leaked. Another 1,947 customers had names, cities, and emails exposed. Trezor said its own systems and hardware wallets were not affected, but victims face heightened risks of phishing impersonating Trezor, banks, or exchanges. Because home addresses were involved, criminals could also target victims for kidnapping or home invasions to steal crypto. The company noted this was its first such breach since 2013. Similar incidents have hit rival Ledger, with past leaks leading to harassment and continued fraud attempts. Recent data shows violent crypto thefts are rising, with over $30 million stolen in the first half of 2026.

Quick Take

  • A breach at Trezor‘s shipping partner ShipMonk exposed customer names and contact information, including nearly 12,000 customers’ phone numbers and shipping addresses.
  • Victims could now be at higher risk of phishing attempts or, in the worst case, targets of violent attacks.

Nearly 14,000 Trezor customers had their personal information exposed in a breach at shipping provider ShipMonk, most of whom had their names, phone numbers and home addresses exposed.

According to a Trezor announcement late Wednesday, ShipMonk informed the hardware wallet manufacturer on Monday that an unauthorized party had accessed the systems holding customer order data.

It specified that the names, email addresses, phone numbers and shipping addresses of 11,742 customers had been exposed. Another 1,947 customers had their names, cities and email addresses leaked, bringing the rough estimate of victims to around 13,700 across the U.S., UK, Sweden, Colombia, Brazil, Italy and Portugal.

Trezor said the breach does not affect its internal systems and that the hardware wallets themselves remain secure.

“This is the first time since Trezor was founded in 2013 that we have experienced a breach that exposed customer phone numbers and shipping addresses,” the company said.

The exposed customers are now at a higher risk of being targeted by phishing campaigns, where attackers may reach out impersonating Trezor, banks or crypto exchanges and use the information in an attempt to trick the users out of more sensitive information or their assets.

Similar incidents have also occurred to rival wallet maker Ledger. In January, Ledger customers were alerted that names and contact information had been exposed following unauthorized access to order data held by third-party e-commerce provider Global-e.

In 2020, a larger Ledger breach exposed information belonging to more than 270,000 customers after attackers accessed marketing and e-commerce data. Names, email addresses, phone numbers and, in some cases, home addresses were later published on a hacking forum, leading to phishing attempts and reports of harassment.

Even six years later, customers still report receiving phone calls and even physical letters from fraudsters impersonating Ledger, trying to trick the customers into giving up their seed phrases or other sensitive information.

But phishing and proxy attempts are the lesser of two evils in cases like this where home addresses are involved. Criminals have become more brazen in using personal information to identify targets for kidnappings, home invasions and other physical attacks intended to force victims to hand over their crypto.

On Wednesday, it was reported that a French couple was targeted in three home invasions in less than a month this summer after moving into a house formerly owned by crypto millionaires whose tax information and address had leaked onto the dark web, according to local reporting.

Recent data from Chainalysis found that more than $30 million had been stolen in violent attacks in the first half of 2026, putting it on pace to surpass 2025's full-year total of $58 million.

免责声明

本文观点仅代表作者个人观点,不构成本平台的投资建议,本平台不对文章信息准确性、完整性和及时性作出任何保证,亦不对因使用或信赖文章信息引发的任何损失承担责任
上一篇

瑞讯银行下调全年业绩指引,上半年加密收入暴跌,股价下滑

下一篇

李林携UMX杀回,加密和股市“领证”:TradFi时刻,整个行业都在狂奔!