- A breach in Trezor’s shipping provider, ShipMonk, led to a data leak affecting users in the US, the UK, Sweden, Colombia, Brazil, Italy, and Portugal.
- It exposed sensitive data of 11,742 customers, including their names, addresses, mobile numbers, and email addresses, making them vulnerable to phishing attempts.
- The incident also partially exposed 1,947 customers, giving away their names, cities, and email addresses.
- A cybersecurity firm warns that over $25 billion is lost to phishing annually.
Trezor, the creator of the first-ever hardware wallet, has recently warned users in seven countries about a data leak exposing their private information. The problem stemmed from a breach in one of its shipping providers.
The Latest Trezor Customer Data Leak
According to Trezor’s announcement, ShipMonk informed them on Monday that unauthorized access to their system has led to a data leak affecting 11,742 customers. The breach on the shipping provider exposed sensitive information, including their full names, shipping addresses, phone numbers, and email addresses. It also resulted in the partial exposure of 1,947 customers, giving hackers access to their names, cities, and email addresses.
The countries affected by the data breach include the US, the UK, Sweden, Colombia, Brazil, Italy, and Portugal. It covers deliveries completed within the past 90 days leading up to August 8. The company explained that the breach is limited due to its strict 90-day data storage policy.
Trezor stated that it already contacted all affected customers via email. Additionally, it assured the public that its hardware wallets and systems remain secure, as the breach is only isolated within ShipMonk’s network. However, it warned that the leak could expose affected users to phishing attempts.
With that, the hardware wallet provider advised users against entering their wallet backup on a website or sharing it with anyone. Moreover, it advised them to only check for updates on official Trezor channels.
Trezor said that an investigation into the incident is ongoing.
Phishing Incidents Worldwide
Phishing involves malicious actors deceiving people into revealing sensitive data or giving them access to their devices through certain actions. The attackers pose as authorized representatives of a legitimate or reputable company to trick them into cooperating.
Criminals often employ this technique to steal crypto from unsuspecting holders. Zensec, a cybersecurity company in the UK, reported that around 90% of cyberattacks begin with phishing. Furthermore, it revealed that malicious actors send approximately 3.4 billion phishing-related emails daily. It detected more than a million phishing attacks in the first quarter of 2025 alone, accounting for billions of dollars in losses annually.
Meanwhile, Astra, another cybersecurity firm, estimates that over $25 billion is lost to phishing annually.







