A data breach at ShipMonk, one of hardware-wallet maker Trezor’s shipping providers, exposed personal information associated with 13,689 customers, creating a heightened risk of targeted phishing and impersonation attempts.
Trezor said 11,742 customers had their names, email addresses, phone numbers and shipping addresses exposed. Another 1,947 customers had their names, cities and email addresses exposed, although the company said it was checking whether some of those partial-exposure records came from older orders.
The incident did not compromise Trezor’s systems, wallet devices, private keys or backups, according to the company. The distinction is important: the immediate danger is not a technical compromise of the wallet, but criminals using accurate identity and order information to make fraudulent communications more convincing.
Shipping data becomes a security issue
ShipMonk informed Trezor on August 10 that an unauthorized party had accessed systems containing customer data. Trezor disclosed the incident on August 13 and said the investigation remained ongoing.
The affected orders were generally delivered between May 10 and August 8 to customers in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal. Trezor said all affected customers were contacted directly by email.
Shipping a physical wallet necessarily involves data that can be valuable to attackers: a customer’s name, delivery address, telephone number, email address and order details can establish both identity and likely ownership of a crypto-security product. That combination can support fake support calls, fraudulent letters, exchange or bank impersonation, and messages designed to pressure a recipient into revealing a wallet backup.
Trezor specifically warned customers never to enter a wallet backup on a website or share it with anyone. A legitimate wallet provider does not need a recovery seed to investigate a delivery or account issue.
Third-party controls are part of wallet security
For wallet companies and other crypto-payment providers, the incident shows why security assessments cannot stop at code, custody and device design. Fulfilment partners, customer-support vendors and commerce platforms may hold data that does not move funds directly but can help an attacker target the people who do.
Trezor said its 90-day data-storage policy, which it also negotiated with fulfilment partners, limited the breach’s scope because older delivery data had been deleted or anonymized. The company nevertheless noted that it was verifying the age of some partially exposed records with ShipMonk.
That uncertainty matters operationally. Providers need retention rules that can be tested against vendor systems, incident notices that identify affected populations precisely, and support processes that do not train customers to disclose secrets. Short retention periods can reduce the amount of data available in a breach, but they do not eliminate the need to monitor whether partners follow them.
What customers and providers should take from the incident
Affected customers should treat unexpected emails, calls, text messages and physical mail referring to their wallet purchase as potentially fraudulent, especially when the sender creates urgency or asks for recovery information. Communications should be checked against official company channels rather than links or contact details supplied in the message.
For providers, the wider lesson is that customer-data exposure can become a payment-security problem even when no transaction system is breached. Accurate personal data can make social engineering more effective, and in self-custody products a successful deception can result in an irreversible transfer.
The incident therefore calls for controls across the full customer journey: minimal data collection, enforceable retention limits, vendor-access monitoring, rapid breach notification and clear rules that staff will never request recovery seeds or private keys. Device security remains essential, but it is only one layer of protection when attackers can target the owner instead.