Trezor Customer Data Exposed in Shipping Partner Breach
Trezor disclosed that a breach at shipping provider ShipMonk exposed customer order data, including names, phone numbers, email addresses, and home addresses. The company said 13,689 customers were affected: 11,742 had full details exposed, while 1,947 had names, cities, and email addresses taken. The orders were shipped to customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal over the prior 90 days. Trezor said its own systems were not breached, and no devices, private keys, or wallet backups were compromised. It said older orders were not exposed because partners are required to delete or anonymize data after 90 days. The company warned customers to watch for phishing and never enter wallet backups online. It also said it is accelerating an Anonymous Delivery option with locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping data.
