AI · CoinDesk
Trezor cautions 14,000 customers after fulfilment partner suffers data breach
Compiled by KHAO Editorial — aggregated from 3 sources. See llms.txt for citation guidance.
✓ KHAO Verified
ShipMonk, Trezor’s fulfillment partner, suffered unauthorized access to its systems, affecting nearly 14,000 customers’ data, the cold storage crypto wallet firm reported Thursday.
Key facts
- Extortionists have leveraged home addresses to demand $700 to $1,000 in ransom and mail counterfeit devices directly to victims
- It said that this year, data breaches have increased by 17% compared with 2025, with an average of 2,090 attacks worldwide each week
- However, Satoshi Labs, the company behind Trezor, reported that a third-party support portal’s security had been breached in January 2024, affecting 66,000 people
- In 2020, Ledger suffered another large-scale breach affecting nearly 300,000 users
Summary
Trezor said nearly 14,000 customers had personal data exposed after its fulfillment partner ShipMonk suffered an unauthorized access to its systems, though its own infrastructure and wallets remain secure. The breach, the first in Trezor’s history to expose customer phone numbers and shipping addresses, increases the risk of phishing and other scams even though no misuse of the leaked data has yet been confirmed. The incident underscores a broader rise in global data breaches and follows earlier third-party leaks affecting Trezor and rival hardware wallet maker Ledger, which have led to long-running phishing and extortion campaigns. Trezor said the names, email addresses, phone numbers and shipping addresses of 11,742 customers had been compromised.