Trezor said a breach at third-party shipping provider ShipMonk exposed personal and order data belonging to 13,689 recent customers, including names and contact details that can be used for targeted phishing. Shipping addresses also create a potential physical-security risk by tying named customers to recent Trezor orders.

In its disclosure, Trezor said 11,742 customers had their full name, email address, phone number and shipping address exposed. Another 1,947 had their name, city and email address exposed.

The affected orders were delivered between May 10 and Aug. 8 to customers in the U.S., U.K., Sweden, Colombia, Brazil, Italy and Portugal. Trezor said ShipMonk informed it on Aug. 10 of unauthorized access to systems containing customer data. The investigation remains ongoing.

Trezor said its own systems were not compromised and that its devices remain secure. All affected customers were contacted separately by email, according to the company; its notice says customers who did not receive an email from help@trezor.io were not affected.

The company warned recipients to expect more sophisticated phishing attempts and said scammers could use the information for fake emails, phone calls and letters, or to impersonate Trezor, a bank or a crypto exchange. It told customers never to enter their wallet backup on a website or share it with anyone, and to verify messages against Trezor's official channels.