According to an announcement on X on August 13, Trezor reported a data breach affecting 13,689 customers from the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who placed orders within 90 days prior to August 8. The Prague-based hardware wallet manufacturer identified ShipMonk, its third-party fulfillment partner, as the source of the unauthorized access.
Of those affected, 11,742 customers had their names, emails, phone numbers, and shipping addresses exposed, while 1,947 customers had only their names, cities, and emails leaked. Trezor stated that its own systems and devices remain secure, but warned affected customers could face increased phishing attempts and fraudulent communications impersonating banks, crypto exchanges, or the company itself.