Hardware wallet maker Trezor has confirmed that a breach at its logistics partner ShipMonk exposed personal data belonging to more than 13,000 customers, and it warned affected users to expect an increase in phishing attempts.
The company said 11,742 customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who ordered Trezor products between May 10 and August 8 had names, email addresses, phone numbers, and shipping addresses exposed. An additional 1,947 customers had names, home cities, and email addresses exposed, and some of those orders may predate May 10, meaning the scope could reach further back than the company’s initial findings.
Trezor is verifying the details and the timeframe with ShipMonk, which stores and ships products on the company’s behalf and collects the information needed to fulfill orders. ShipMonk operates under a 90-day retention policy that requires partners to delete or anonymize customer data within 90 days of collection.
The company stressed that its own systems and hardware devices remain secure, a reassurance consistent with its positioning as a vendor of offline, hardware-based cryptocurrency wallets. But the exposed data is exactly the kind of profile that fuels targeted phishing aimed at cryptocurrency holders.
The Register noted that Trezor did not address the physical-attack angle: France has seen multiple cases of wealthy cryptocurrency holders, or their relatives, kidnapped by robbery gangs, and a shipping address tied to a crypto wallet purchase is a valuable piece of information in that context.
Affected customers should treat unsolicited messages referencing Trezor or ShipMonk with suspicion, avoid clicking links in unexpected emails, and be wary of anyone contacting them about order details. The incident is a reminder that even companies with strong product security can be exposed through their supply chain.
