Trezor reports data from 14K users exposed through shipping provider

Summary

Trezor said a breach at its shipping provider, ShipMonk, exposed personal data for about 14,000 customers and could enable phishing attacks. Affected users received products in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal between May 10 and Aug. 8. About 11,742 customers may have had names, physical addresses, phone numbers, and email addresses exposed; another 1,947 may have had names, cities, and email addresses compromised. Trezor said its own systems were not breached and device security was not affected, but attackers could use the leaked data to send fake emails, calls, letters, or impersonate banks, crypto exchanges, or Trezor itself. This follows earlier phishing risk disclosures tied to prior support interactions.