Particle.news
Download on the App Store

ShipMonk Breach Exposes Personal Data of 13,689 Trezor Customers

The leak increases the risk of targeted phishing and home-focused attacks, prompting Trezor to fast-track an anonymized delivery option as the incident is investigated.

Overview

  • ShipMonk told Trezor on Monday, Aug. 10 that its systems had been accessed without authorization, and Trezor publicly disclosed the breach on Thursday, Aug. 13 affecting recent orders.
  • A total of 13,689 customers were affected, with 11,742 people having names, emails, phone numbers and shipping addresses exposed and 1,947 others having partial details such as name, city and email.
  • Trezor says its own systems and hardware wallets were not compromised and that no device, private key or wallet backup was accessed.
  • Trezor has emailed affected customers, warned them to expect more convincing phishing and impersonation attempts, and is accelerating an Anonymous Delivery option that uses locker pickup, neutral packaging and automatic deletion of shipping identifiers.
  • The incident highlights persistent third‑party supply chain risk for hardware‑wallet users and follows earlier e‑commerce partner leaks and recent device exploits, raising concern that exposed addresses could enable physically targeted attacks as well as online fraud.