Trezor Users Targeted by Phishing Calls & QR Letters

Help Net Security · Medium sophistication
Last updated September 9, 2026

After a breach at shipping partner ShipMonk, attackers obtained Trezor customers’ contact and shipping details, increasing the risk of scams. Reports on Reddit indicate customers have already received phishing phone calls and physical letters containing QR-code phishing lures. Trezor warned customers to watch for scam emails, calls, and letters and noted the leak could also create physical safety risks.

How the attack unfolded

This case began not with a hack of Trezor's own systems but with a breach at ShipMonk, a shipping partner that handled order fulfillment. That breach exposed customer names, email addresses, phone numbers, and shipping addresses. Trezor has stated that its own infrastructure was not compromised and that customer devices remain secure, but the exposed contact and shipping data still gave attackers enough material to run convincing scams.

Customers began reporting two distinct follow-on attacks. Some received phishing phone calls, likely referencing real order details to sound legitimate. Others received physical letters containing QR codes, a channel that is harder for typical security awareness training to cover since it does not arrive by email.

Why this approach worked

The scams succeeded because they combined real, leaked personal details with unusual delivery channels. A caller who knows your name, address, and that you recently ordered a hardware wallet sounds credible, especially when the pretext is framed as a delivery or security verification issue. Similarly, a physical letter with a QR code bypasses email spam filters and browser warnings entirely, and recipients may not expect phishing to arrive through the mail.

What to watch for

  • Unsolicited calls referencing your home address or order history
  • Pressure to "verify" sensitive information over the phone
  • Callers whose identity cannot be confirmed through official published contact channels
  • Physical letters urging you to scan a QR code to "secure" your wallet or order
  • Unexpected, urgent security verification requests delivered by mail

Building resistance

Trezor has advised customers to treat any unexpected call, email, or letter referencing their order as suspicious and to verify through official channels before acting. Customers should avoid scanning QR codes from unsolicited letters and instead navigate directly to the vendor's known website. Trezor is also reportedly working on more anonymous delivery options, including locker pickup, neutral packaging, generic sender details, and automatic deletion of shipping identifiers after delivery.

More broadly, anyone purchasing high-value items like crypto hardware wallets can reduce exposure by using an anonymous email address for orders and limiting public disclosure of their holdings. Because crypto holders can face elevated real-world risk, minimizing the trail of personal data tied to a purchase, and staying alert to both digital and physical phishing attempts, is a practical way to reduce follow-on risk after any third-party data exposure like this one.

Key findings

  • Customer names, email addresses, phone numbers, and shipping addresses were exposed in a breach at shipping partner ShipMonk.
  • SatoshiLabs says the leaked data could be used for scam emails, fraudulent calls, or physical letters, and could create physical security risks.
  • Customers reported receiving phishing calls and QR-code phishing delivered via physical letter.
  • Trezor says its own systems were not compromised and customers’ devices are secure.
  • Trezor is working on options for more anonymous delivery (e.g., locker pickup, neutral packaging, generic sender details, auto-deletion of shipping identifiers).

Who’s being targeted

  • Commonly targeted roles: All employees (personal-device/identity protection), Executives, Finance teams (high-value targets), Customer support teams (for handling scam reports).
  • Affected industries: Cryptocurrency, Consumer finance, E-commerce/online retail logistics.
  • Attack channels: vishing, physical, website.
  • Impersonated: Trezor support or the shipping provider, Trezor (or a delivery/shipping service).

Red flags to watch for

  • Unsolicited call referencing your home address/order history
  • Pressure to ‘verify’ sensitive information over the phone
  • Caller identity cannot be verified via official published contact channels
  • Physical letter pushing you to scan a QR code to ‘secure’ funds
  • Unexpected “urgent” security verification request
  • QR code obscures the true destination website
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers get Trezor customer data for these scams?

A breach at Trezor's shipping partner, ShipMonk, exposed customer names, email addresses, phone numbers, and shipping addresses, which could then be used to craft convincing scam contacts.

What kinds of scams have Trezor customers reported?

Customers reported receiving phishing phone calls and physical letters containing QR codes designed to lure recipients into scanning them, according to reports on Reddit.

Was Trezor itself hacked?

Trezor says its own systems were not compromised and that customers' devices remain secure; the exposure came from its shipping partner ShipMonk.

What should Trezor customers do if they receive a suspicious call or letter?

Treat any unexpected Trezor-related call, email, or letter as suspicious and verify it using known official channels before acting, and avoid scanning QR codes from unsolicited letters.

Read the video transcript

You get a call: “Hi, I’m from Trezor support about your recent order at this address…” and they read out your home address. After a breach at shipping partner ShipMonk, scammers got real Trezor customer names, emails, phone numbers, and shipping addresses. Now they’re using them for phishing calls and fake security letters with QR codes. The trick: they sound legit because they know your last Trezor order and address, then push you to ‘verify’ details or scan a QR code to secure your wallet. That site or call flow is built to steal your seed phrase or funds. If anything Trezor-related contacts you out of the blue, call, email, or letter, do one thing: hang up or ignore it, then go to trezor.io yourself and use the official support contact from there.

Similar attacks

AI-Aided Crypto Scam Used Phishing + Vishing Combo

AI-Aided Crypto Scam Used Phishing + Vishing Combo

Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those…

August 19, 2026
Fraud Ring Targets Crypto Users via Phone + Phish

Fraud Ring Targets Crypto Users via Phone + Phish

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands,…

August 18, 2026
Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026