Trezor says a ShipMonk breach exposed names, addresses, phone numbers and emails for 11,742 customers, creating a targeted-phishing risk but no reported wallet compromise.