Hardware wallet maker Trezor reports data breach after shipping partner hack

Hardware wallet maker Trezor reports data breach after shipping partner hack

Trezor says a breach at logistics provider ShipMonk exposed order data for nearly 14,000 customers, including names and addresses. Affected users should watch for phishing attempts.

Hardware wallet manufacturer Trezor has disclosed a data breach that exposed order information for nearly 14,000 of its customers. The incident originated at ShipMonk, a shipping and logistics provider that Trezor uses to fulfill orders. A hardware wallet is a physical device that stores cryptocurrency private keys offline, keeping them away from internet-connected computers where they could be stolen by hackers. The breach did not affect Trezor's own systems, but it did expose customer data held by the third-party shipper.

According to Trezor, the attackers gained access to order data including full names, shipping addresses, email addresses, and phone numbers for 11,742 customers. An additional 1,947 customers had partial exposure, specifically their name, city, and email address. The affected customers are located in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, and they placed orders between May 10 and August 8, 2026. ShipMonk informed Trezor of the unauthorized access on Monday, August 10, 2026.

Trezor stressed that its own infrastructure was not compromised and that all Trezor devices remain secure. However, the company warned affected customers to be on high alert for phishing attempts. Scammers can use the leaked information to send fake emails, make deceptive phone calls, send fraudulent letters, or impersonate banks, cryptocurrency exchanges, or even Trezor itself. This warning is particularly important because Trezor experienced a similar breach in January 2024, when attackers accessed its third-party support ticketing portal and exposed the names, usernames, and email addresses of 66,000 users. Those details were later used in phishing campaigns that tried to trick victims into revealing their 24-word recovery seeds, which are the secret phrases that control access to cryptocurrency funds.

The ShipMonk breach was caused by a vulnerability in Metabase, a third-party analytics platform used by the shipping provider. ShipMonk told affected customers that on August 6, 2026, Metabase informed them that an unauthorized party exploited a vulnerability in Metabase's software to access data. Metabase later revealed that the attackers used a critical SQL injection zero-day vulnerability. A zero-day vulnerability is a security flaw that is unknown to the software vendor and has no patch available at the time of attack. SQL injection is a technique where an attacker inserts malicious code into a database query, potentially gaining access to or modifying data. After exploiting the vulnerability, the attackers gained administrator access to the compromised Metabase instance. Metabase has since patched the vulnerability and invalidated all active sessions. ShipMonk also initiated an investigation with external IT experts. Other companies affected by the same Metabase vulnerability include laptop maker Framework and online form builder Tally. BleepingComputer has learned that ShipMonk has also received extortion emails from the ShinyHunters extortion gang.

In a related development, video game distribution giant Valve also notified Steam hardware customers in Europe that hackers stole their data after hacking CEVA Logistics, its shipping partner. This pattern highlights the growing risk of supply chain breaches, where attackers target a service provider to steal customer data from multiple companies at once. For website owners and businesses, this incident is a reminder that even if your own systems are secure, your customers' data can be exposed through third parties you rely on for shipping, analytics, or other services. Assessing the security practices of your vendors and preparing your customers for potential phishing attacks are essential steps in a modern security strategy. For businesses that want to reduce their exposure to such third-party risks, AEU-I's security-first IT and consulting services can help identify and mitigate supply chain vulnerabilities before they lead to customer data exposure.

How to Protect Yourself

  1. If you receive an unexpected message about your Trezor order, do not click any links or download attachments; instead, go directly to the official Trezor website by typing the address yourself.
  2. Never share your 24-word recovery seed with anyone, even if a message claims to be from Trezor support; Trezor will never ask for it.
  3. Check the sender's email address carefully for misspellings or unusual domains, as scammers often use look-alike addresses to trick you.
  4. Turn on two-step verification (a code sent to your phone) for your email and other important accounts to add an extra layer of security.
  5. If you are unsure whether a message is real, contact the company directly using a phone number or email address from their official website, not from the message you received.
  6. Regularly review your bank and credit card statements for suspicious activity, especially if your shipping address and phone number were exposed.

Related AEU services

  • AEU-I IT and security consulting