ShipMonk disclosed the unauthorized access to its systems on August 10, prompting an investigation into how order data was intercepted. The breach affected customers who received deliveries between May 10 and August 8 in regions including the U.S., U.K., Brazil, and Italy. Of those impacted, 11,742 individuals had their full contact details exposed, while 1,947 had partial information compromised. Trezor emphasized that its 90-day data retention policy limited the scope of the leak, as older records had already been scrubbed.
In section Cryptocurrency
Trezor Customer Data Exposed in ShipMonk Logistics Breach
A security breach at shipping provider ShipMonk has compromised the personal data of 13,689 Trezor customers. While hardware wallets and Trezor’s internal systems remain secure, the incident has exposed names, phone numbers, and home addresses, heightening the risk of targeted phishing attacks against users across multiple countries.

Although the breach did not compromise private keys or wallet infrastructure, the leaked information presents a significant risk for social engineering. Attackers often leverage physical addresses and phone numbers to craft convincing phishing campaigns, including fraudulent letters or calls that mimic official support channels. Trezor advised users to remain vigilant against any communications requesting recovery phrases or immediate action. To mitigate future risks, the company plans to introduce an Anonymous Delivery service, targeting a European launch by September 2026 and a U.S. rollout by the end of that year.
Comments (0)
No comments yet. Be the first!