Trezor, the cold storage crypto wallet maker, said Thursday that nearly 14,000 customers' personal data was exposed after its fulfilment partner ShipMonk suffered unauthorized access to its systems. The company said the breach affected customers in the U.S., the UK, Sweden, Colombia, Brazil, Italy and Portugal.
According to Trezor, the names, email addresses, phone numbers and shipping addresses of 11,742 customers were compromised. Another 1,947 customers had their names, cities and email addresses exposed, bringing the estimated number of victims to nearly 14,000.
"We have some difficult news to share," Trezor said on X. "Unfortunately, one of our shipping providers has experienced a data breach that exposed sensitive order data."
Trezor said its own systems were not compromised and its wallet devices remain secure. The company told CoinDesk it has no confirmed cases of the exposed data being published, shared, or offered for sale, and it is unaware of any scam or hack attempt linked to the incident so far. Customers who purchased through Amazon are not affected, as those orders are fulfilled by a separate partner.
The company said affected customers are now more likely to be targeted by phishing attempts via email, phone, or post. Scammers could use the leaked data to impersonate banks, crypto exchanges, or Trezor itself.
Trezor said this was the first breach in its 13-year history to expose customer phone numbers and shipping addresses. However, Satoshi Labs, the company behind Trezor, reported that a third-party support portal's security had been breached in January 2024, affecting 66,000 people. Another 106,856 Trezor customers' data was compromised in April 2022. Trezor's internal firmware and on-device cryptography have never been breached remotely to steal funds.
The incident comes as global data breaches are at an all-time high, according to SentinelOne, a U.S. cybersecurity firm. It said that this year, data breaches have increased by 17% compared with 2025, with an average of 2,090 attacks worldwide each week. It is also estimated that global data breaches have been rising by 3% month over month since January.
Ledger, the maker of one of the most popular hardware wallets in crypto, suffered a data breach in January. The security breach was linked to its third-party e-commerce partner, Global-e. In 2020, Ledger suffered another large-scale breach affecting nearly 300,000 users. A year later, scammers sent fake Ledger devices to victims of that breach in a follow-on phishing campaign.
People whose data is stolen in a data breach remain at risk for years after the hacking event. Once stolen logistics records are sold or published online, cybercriminals continually repurpose the data for new scams. Extortionists have leveraged home addresses to demand $700 to $1,000 in ransom and mail counterfeit devices directly to victims. Managing the long-tail legal, remediation, and brand fallout from a major customer leak is estimated to cost hardware firms over $33 million.
Crypto holders are also increasingly at risk of physical attacks. In-person coercion attacks have totalled $124 million in the first half of this year alone, although not all can be traced back to a data breach, according to Certik. Cybersecurity firm DeepStrike estimated the amount of money people lose to data breaches into the tens of billions of dollars yearly.



