14,000 Trezor Customers Exposed in Fulfilment Partner Breach

Trezor has alerted nearly 14,000 customers after its fulfillment partner, ShipMonk, suffered unauthorized access that exposed sensitive customer information.

The company said the incident is the first breach in its history to expose customers’ shipping addresses.

Trezor said data belonging to 11,742 customers, including names, email addresses, phone numbers and shipping addresses, was compromised. A further 1,947 customers had their names, cities and email addresses exposed. The affected users are spread across the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal.

The hardware wallet manufacturer disclosed the breach Thursday, saying one of its shipping providers had experienced unauthorized access involving customer order data.

The incident comes amid a broader increase in data breaches worldwide. Cybersecurity firm SentinelOne reported that breaches have risen 17% compared with 2025, averaging 2,090 attacks globally each week. The number of incidents has also reportedly increased by about 3% month over month since January.

Trezor said it emailed every customer affected by the incident and confirmed that customers who did not receive a notification were not impacted. The company told CoinDesk that it has not found evidence that the compromised information has been published, circulated or offered for sale.

The company also said it has not identified any scams or hacking attempts tied to the breach. Customers who bought Trezor devices through Amazon were not affected because those orders are handled by a different fulfillment provider.

Trezor Says Wallets and Funds Are Secure

Trezor emphasized that the breach did not involve its own systems. The company said its hardware wallets remain secure and that customer cryptocurrency was not directly compromised.

The main risk involves potential phishing and social-engineering attacks. Criminals could use exposed names, phone numbers, email addresses or home addresses to impersonate Trezor, financial institutions or crypto exchanges.

Data stolen during a breach can remain useful to criminals for years. Shipping information can be reused in future phishing campaigns, fraud schemes and other targeted attacks if it is later distributed or sold.

Attackers have previously used leaked residential addresses to demand ransoms of $700 to $1,000 or send counterfeit hardware devices to victims. Major customer data breaches can also leave companies facing significant legal, remediation and reputational costs.

Physical threats are another growing concern for crypto users. CertiK reported that in-person coercion attacks involving cryptocurrency holders totaled $124 million in the first half of the year, although not every incident was connected to a data breach. DeepStrike estimates that data breaches cost victims tens of billions of dollars globally each year.

Previous Trezor Data Incidents

Trezor said the latest breach is the first in its 13-year history to expose customer phone numbers and shipping addresses.

The company has previously dealt with security incidents involving third-party services. Satoshi Labs, the company behind Trezor, disclosed a breach of an external support portal in January 2024 that affected 66,000 people. Another incident in April 2022 compromised information belonging to 106,856 Trezor customers.

Trezor said its internal firmware and on-device cryptographic systems have never been remotely breached to steal customer funds.

Ledger, another major hardware wallet manufacturer, has also experienced third-party data breaches. A January incident was linked to its e-commerce provider Global-e, while a larger breach in 2020 affected nearly 300,000 users. In 2021, scammers used information from that breach to conduct a phishing campaign involving fake Ledger devices sent to affected customers.