en
Back to the list

Trezor warns 14,000 customers after fulfilment partner suffers data breach

source-logo  coindesk.com 13 August 2026 17:27, UTC
image

ShipMonk, Trezor’s fulfillment partner, suffered unauthorized access to its systems, affecting nearly 14,000 customers’ data, the cold storage crypto wallet firm reported Thursday.

Trezor said the names, email addresses, phone numbers and shipping addresses of 11,742 customers had been compromised. It also said the names, cities and email addresses of another 1,947 customers were also breached, bringing the estimated number of victims to nearly 14,000 across the U.S., the UK, Sweden, Colombia, Brazil, Italy and Portugal.

"We have some difficult news to share," Trezor said Thursday on X. "Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data."

The Trezor-related security hack comes as global data breaches are at an all-time high, according to SentinelOne, a U.S. cybersecurity firm. It said that this year, data breaches have increased by 17% compared with 2025, with an average of 2,090 attacks worldwide each week. It is also estimated that global data breaches have been rising by 3% month over month since January.

The cold storage wallet manufacturing firm said it notified all affected customers via email, adding that the data of those who did not receive the message was not compromised. Trezor told CoinDesk via email it has no confirmed cases of the exposed data being published, shared, or offered for sale yet. It also said it is unaware of any scam or hack attempt linked to the incident so far. Customers who purchased through Amazon are not affected, as those orders are fulfilled by a separate partner, it added.

Trezor also said its own systems were not compromised, and crypto wallet devices remain secure. The risk is indirect, it added, saying affected customers are now more likely to be targeted by phishing attempts via email, phone, or post. Scammers could use the leaked data to impersonate banks, crypto exchanges, or Trezor itself.

People whose data is stolen in a data breach remain at risk for years after the hacking event. Once stolen logistics records are sold or published online, cybercriminals continually repurpose the data for new scams. Extortionists have leveraged home addresses to demand $700 to $1,000 in ransom and mail counterfeit devices directly to victims. Managing the long-tail legal, remediation, and brand fallout from a major customer leak is estimated to cost hardware firms over $33 million.

coindesk.com