A data breach at Trezor's fulfillment partner ShipMonk exposed personal data for nearly 14,000 customers—the first time in the company's 13-year history that customer phone numbers and shipping addresses were compromised.

The breach hit 11,742 customers whose names, email addresses, phone numbers and shipping addresses were exposed. An additional 1,947 customers had their names, cities and email addresses compromised.

Trezor confirmed the breach Thursday, saying on X that "one of our shipping providers has experienced a data breach that exposed sensitive order data." The company said it notified all affected customers via email.

Customers across seven countries were impacted: the U.S. the U.K. Sweden, Colombia, Brazil, Italy and Portugal. The breach targeted customers who received an order in the 90 days before Aug. 8.

The compromise came through unauthorized access to ShipMonk's systems. Trezor said its own systems were not compromised and that crypto wallet devices remain secure. Orders placed through Amazon were also unaffected, as a separate partner fulfills those shipments.

The immediate risk for affected customers centers on phishing. Scammers can use exposed names, email addresses, phone numbers and shipping addresses to impersonate banks, crypto exchanges or Trezor itself.

Long-term exposure runs dee. Stolen logistics records get recycled into new scams for years. Extortionists have used home addresses to demand $700 to $1,000 in ransom. Others have mailed counterfeit devices directly to victims.

Hardware firms face real financial damage from leaks like this. Legal, remediation and brand costs from a major customer data exposure can exceed $33 million—before counting any direct customer losses.

Physical security is the sharpest risk for crypto holders with exposed addresses. CertiK reported in-person coercion attacks totaled $124 million in the first half of this year. Not all traced back to data breaches, but exposed home addresses raise this threat directly.