Shipping Partner Breach Exposes Personal Information of 14,000 Trezor Customers
Approximately 14,000 customers of Trezor face the possibility of becoming targets for "sophisticated phishing attempts" following a security incident that occurred at the company's logistics partner.

The hardware wallet manufacturer Trezor has disclosed a security incident involving the exposure of customer information belonging to approximately 14,000 individuals, which occurred at ShipMonk, the company's third-party shipping provider.
In a blog post published on Wednesday, Trezor indicated that customers who had received their hardware products from facilities located in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal during the period spanning May 10 through Aug. 8 face potential exposure to phishing campaigns leveraging their personal details. According to the company's disclosure, 11,742 affected individuals may have experienced the compromise of their full name, residential address, telephone number, and email contact information, whereas an additional 1,947 customers potentially experienced exposure of their full name, city of residence, and email address.
To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts. Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even Trezor.
This security incident represents the most recent occurrence in a pattern of events where fraudsters have potentially obtained access to personal information of cryptocurrency holders. In January 2024, Trezor previously disclosed that roughly 66,000 of its customers faced exposure to phishing schemes if they had initiated contact with the company's customer support department at any point after December 2021.
Individuals who use cryptocurrency wallets have documented that fraudulent actors employ a diverse array of tactics in their efforts to obtain unauthorized access to digital assets, including the distribution of physical correspondence through postal mail. Additional attack vectors include short message service communications, electronic mail messages, and voice calls where perpetrators falsely claim to be relatives requiring emergency assistance or pose as government officials demanding settlement of fabricated outstanding debts.