Trezor Announces Data Leak of Over 13,000 Customers Due to ShipMonk Hack
Trezor has reported a data breach affecting 13,689 of its customers due to a hack of its logistics partner, ShipMonk. The incident impacted customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received orders in the 90 days prior to August 8th.
Trezor emphasized its own systems and devices were not compromised, but the leaked data could facilitate more sophisticated phishing attacks against affected users. Full data for 11,742 customers was exposed, including name, email, phone number, and delivery address. Partial data (name, city, and email) for 1,947 others was also accessed.
ShipMonk stored the delivery information, and Trezor noted the incident was limited by ShipMonk's policy to delete or anonymize order data 90 days after delivery. This is Trezor's first breach since 2013 involving customer phone numbers and physical addresses. Private keys, wallet backups, and devices remain secure.
All affected customers have been notified. Trezor is investigating with ShipMonk, which has secured the affected systems.
In response, Trezor announced plans for an anonymous delivery feature in the EU by September 2026 and in the US by year-end, aiming to minimize personal data collection through pseudonyms, automated pickup points, and post-delivery data deletion.
cryptonews.ru1h ago