In brief
- A breach at ShipMonk, one of Trezor's fulfillment partners, exposed personal data belonging to 13,689 Trezor customers.
- Full names, phone numbers, email addresses and shipping addresses were taken for 11,742 of them.
- Trezor says no device, private key or wallet backup was affected, and that its systems were not compromised.
A data breach at one of Trezor's shipping providers has exposed the names, phone numbers, email addresses and home addresses of thousands of the hardware wallet manufacturer's customers, the company disclosed on Thursday.
ShipMonk, which stores and ships Trezor's products, told the company on Monday that an unauthorized party had reached systems holding customer data. Some 11,742 customers had their full details taken and another 1,947 had names, cities and email addresses exposed, a total of 13,689. Those affected placed orders between May 10 and August 8 and had them shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy or Portugal.
Trezor said its own systems were not compromised and that no device, private key or wallet backup was touched. It attributed the limited scope to a policy requiring partners to delete or anonymize order data 90 days after delivery, which meant older orders were no longer held. Customers who did not receive a notification email are not affected, it said. In 13 years, the company added, it has never before had a breach exposing customer phone numbers and shipping addresses.




