Trezor data breach: ShipMonk exposed ~14,000 customers’ details, warns of phishing

Hardware wallet maker Trezor said a breach at its fulfillment partner ShipMonk led to a Trezor data breach affecting nearly 14,000 customers. Trezor reported that 11,742 customers had full details exposed (full name, email, phone number, and shipping address), while 1,947 customers had partial exposure (name, city, and email). Affected customers are in the U.S., the UK, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor emphasized that its own systems, wallet devices, and cryptographic security were not compromised. It has not confirmed that any stolen data has been published, shared, or sold, and it said it is not aware of related scam attempts so far. It also noted that orders placed via Amazon were not impacted because a different fulfillment partner handled them. The key trading-relevant risk from this Trezor data breach is indirect: leaked logistics and contact data can enable targeted phishing and impersonation scams by email, phone, or mail, potentially posing as banks, crypto exchanges, or Trezor. Trezor also highlighted it is increasing an “Anonymous Delivery” option to reduce shipping-identifier exposure, aiming for rollout in the EU by September and in the U.S. by year-end.
Neutral
This is primarily a consumer-security and fraud-exposure event, not a protocol or token-technology change. Trezor said the breach did not compromise its own infrastructure or any private keys, which limits direct downside for crypto assets. However, the incident can raise scam activity (phishing/impersonation) and keep some retail sentiment around self-custody under pressure, which may create short-lived noise in broader market sentiment. Net effect on crypto prices is expected to be neutral.