Trezor reported a breach at its shipping provider Shipmonk that exposed personal order data for roughly 13,689 recent customers. The incident raises the risk of targeted scams, but the company says the hardware wallets themselves are not compromised.
What the breach exposed
The exposed data is limited to order information. It doesn't include wallet keys, recovery seeds, or anything that would let someone access a device. Trezor said the breach affects orders placed in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal. The company didn't specify which exact fields were exposed, but the data is enough to make phishing attempts more convincing.
Why the wallets are safe
Trezor emphasized that the breach does not compromise the hardware wallets. The wallets store private keys offline, and the shipping data is separate from the device security. So the funds are not at risk from this incident. That's the good news. The bad news is that the stolen data can be used for social engineering.
The scam risk
The bigger concern is targeted scams. With order details in hand, attackers could craft messages that look like they come from Trezor or Shipmonk. They might reference a recent purchase to build trust. Trezor said the breach increases the risk of such scams. That means customers should be wary of unsolicited emails, texts, or calls that mention their order.
Who is affected
The affected customers are those who placed orders in the seven countries listed. The number is about 13,689, which is a small fraction of Trezor's user base, but still significant. Trezor has not said how it will help affected customers guard against the heightened scam risk. The company has not announced a timeline for individual notifications or any additional security measures.




