AUTO-UPDATED

Trezor warns 14,000 customers after fulfilment partner suffers data breach

Trezor reported that a security breach at its fulfillment partner, ShipMonk, exposed the personal contact and shipping information of nearly 14,000 customers across several global regions.

Key Points

  • Approximately 14,000 Trezor customers had names, email addresses, phone numbers, and shipping addresses compromised in a third-party data breach.
  • The incident occurred at ShipMonk, a logistics provider, though Trezor confirmed its own internal infrastructure and hardware wallets remain secure.
  • Affected customers are located in the U.S., UK, Sweden, Colombia, Brazil, Italy, and Portugal.
  • Trezor stated there is no evidence that the stolen data has been misused or sold, but warned users to remain vigilant against phishing attempts.
  • This marks the first time in Trezor’s 13-year history that customer phone numbers and physical addresses have been exposed in a security incident.

Why it Matters

This breach highlights the persistent security risks associated with third-party vendors in the hardware wallet industry, where customer data is often stored outside of the primary manufacturer's control. While the devices themselves remain secure, the exposure of physical addresses and contact details increases the long-term risk of targeted phishing, extortion, and physical coercion attempts against crypto holders.
CoinDesk Published by Olivier Acuna
Read original