Trezor warns 14,000 customers after fulfilment partner suffers data breach
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Trezor reported that nearly 14,000 customers had personal data exposed due to an unauthorized access incident at its fulfillment partner, ShipMonk. The compromised information includes names, email addresses, phone numbers, and shipping addresses. Trezor's own systems and wallets were not breached, and no misuse of the leaked data has yet been confirmed.
Why it matters
The breach increases the risk of phishing, scams, and extortion against affected customers, as their personal data can be used for impersonation through email, phone calls, or postal services. The incident reflects a broader, ongoing rise in global data breaches affecting the crypto industry and highlights the lasting risks data breach victims face.
Key context
This is the first time Trezor has had a breach exposing customer phone numbers and addresses in its 13-year history, though prior incidents compromised customer emails. The breach follows similar data leaks affecting Trezor and competitor Ledger, which have led to sustained phishing and extortion campaigns. Physical attacks against crypto holders are increasingly common, with hundreds of millions lost through coercion attempts recently.
Key numbers and entities
Nearly 14,000 Trezor customers were affected, including 11,742 with full contact details leaked and 1,947 with partial details exposed. Affected customers span multiple countries, including the U.S., the UK, Sweden, Colombia, Brazil, Italy, and Portugal. Prior breaches involved 66,000 people in January 2024 and over 106,000 in April 2022. Ledger also suffered breaches impacting tens of thousands in recent years.
What remains unclear
Trezor indicates no confirmed cases yet of the stolen data being published, shared, or sold, and no scams are linked to the breach so far. It is unclear if and when such misuse may occur. The source does not flag additional open questions.