A breach at fulfilment partner ShipMonk exposed home addresses and phone numbers for 11,742 Trezor customers, with partial data taken for 1,947 more. No device, key or backup was touched, which is precisely why the leak matters.