Crypto World

Trezor Data Breach Exposes Personal Details of Nearly 14,000 Customers

Published

on

A security incident at a Trezor shipping provider exposed personal details belonging to 13,689 customers.

The breach affected customers across seven countries, while Trezor confirmed that its wallet systems and devices remain secure.

However, the company warned that exposed details could increase phishing attempts targeting affected users.

Shipping Provider Incident Led to Data Exposure

The incident began after ShipMonk, a shipping provider used by Trezor, suffered unauthorized access to its systems.

Advertisement

As a result, attackers accessed customer information linked to hardware wallet orders processed through the provider.

The exposed information includes names, email addresses, phone numbers, and shipping addresses for some affected customers.

Trezor identified 11,742 customers whose information received full exposure during the incident. Those records included customer names, email addresses, phone numbers, and shipping addresses linked to their orders.

Meanwhile, another 1,947 customers faced partial exposure involving their names, cities, and email addresses.

Advertisement

The affected customers received orders in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal. Trezor said those orders fell within the 90 days before August 8, 2026, when the incident came to light.

Furthermore, the company contacted affected customers through its official email channel and advised them to remain alert.

Trezor Warns Customers About Phishing Threats

Although the breach exposed personal information, Trezor said attackers did not compromise its internal systems.

The company also confirmed that its hardware wallets remain secure and that customer funds remain protected by wallet security.

Advertisement

Therefore, the incident primarily creates a social engineering risk rather than a direct device security threat.

However, leaked contact and shipping information could help criminals create more convincing phishing messages.

Attackers could combine customer names, addresses, and emails to make fraudulent messages appear linked to Trezor orders. Consequently, affected users could face attempts to obtain wallet credentials, recovery phrases, or other sensitive information.

Trezor customers should therefore avoid links from unexpected messages and verify communications through official channels.

Advertisement

Users should also never provide recovery phrases, because legitimate wallet providers do not require those details.

In addition, customers should treat unexpected calls, emails, and messages as potential attempts to steal wallet access.

Trezor Develops Anonymous Delivery Option

The breach has also pushed Trezor to develop a new Anonymous Delivery option for future customers.

The company plans to introduce the service in the European Union by September and in the United States later.

Advertisement

This approach aims to reduce the personal information connected with hardware wallet purchases and deliveries.

The planned option could allow customers to use nicknames or label identification instead of real names.

It could also support automated parcel lockers, which would reduce the need to provide home delivery addresses.

Furthermore, Trezor plans to offer unbranded packaging with generic sender information for additional privacy.

Advertisement

The move highlights the security challenges that crypto companies face beyond their own technology and wallets.

Shipping partners can hold valuable customer information, which makes third-party data protection important for hardware wallet users.

As Trezor responds to the incident, stronger delivery privacy could help reduce similar exposure in future orders.

The incident also follows a separate Coldcard security incident that raised concerns across the crypto self-custody sector.

Advertisement

Galaxy Research estimated that users lost as much as $116 million in Bitcoin during that incident.

Together, the events highlight how personal data and wallet security can create different risks for crypto users.

Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

Advertisement

Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version