Trezor Breach: 67,000 US Records Exposed via ShipMonk

Trezor Breach: 67,000 US Records Exposed via ShipMonk

Trezor says a breach at shipping provider ShipMonk exposed 67,000 US customers' personal and order data despite written deletion assurances.

Trezor, the hardware wallet manufacturer, disclosed on Friday that a data breach at its shipping provider ShipMonk exposed personal and order information belonging to 67,000 customers in the United States. The compromised records include customer names, email addresses, phone numbers, shipping addresses, and order numbers tied to purchases made between November 2019 and August 2021. Trezor emphasized that the breach does not affect the security of its hardware wallets, which store cryptocurrency private keys offline. The incident is a supply chain breach: attackers compromised a third-party logistics vendor and, through that vendor, reached order data that Trezor believed had been deleted.

The disclosure expands an earlier notice. Last month, Trezor reported that 13,689 customers had their data either fully or partially exposed. At that time, the company said the breach was limited to data within its 90-day storage policy. Now Trezor says ShipMonk informed it of unauthorized access to the shipping provider's systems on August 10, 2026. Following that notification, ShipMonk revealed that an additional 1,947 customers whose exposure had been limited only to names, cities, and email addresses, without shipping addresses, may include older orders. Trezor said it repeatedly requested and received written assurance from ShipMonk that the data had been deleted, in line with its contract, data policy, and past communications. The company expressed disappointment that, despite receiving this confirmation, the data was not deleted in the vendor's systems.

The breach has been linked to a zero-day vulnerability in Metabase, a data analytics and business intelligence tool. According to enterprise blockchain security firm Holborn, the attackers exploited CVE-2026-72898, a critical SQL injection flaw with a CVSS score of 10.0, the highest possible severity rating. A SQL injection attack works by inserting malicious code into a database query, allowing an attacker to view or change data they should not have access to. Holborn said the ShinyHunters extortion gang is believed to be behind the breach. The firm described the incident as a software supply chain attack that began with the zero-day vulnerability. By finding and exploiting the flaw in Metabase, the attackers were able to reach several of its customers, steal sensitive data, and extort the affected organizations. In Trezor's case, this meant the exposure of customer order details that were stored in a Metabase instance run by ShipMonk. ShipMonk has not yet publicly acknowledged the incident. The logistics company is said to have secured the affected systems and improved its security after the digital break-in.

For the affected Trezor customers, the main risk is not theft of cryptocurrency from the hardware wallets themselves, but social engineering and scams built on the leaked order details. Trezor said it has notified affected customers directly and warned them to be on the lookout for phishing emails, fraudulent letters, and fake phone calls. Attackers can use the exposed names, email addresses, phone numbers, shipping addresses, and order numbers to make their messages look convincing. They may impersonate Trezor in email communications and try to persuade targets into taking actions such as revealing a wallet recovery phrase or moving funds. Trezor warned that the leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks. Because the data includes physical shipping addresses, customers should also be alert to possible attempts to use that information in person or by mail.

Holborn said the attack highlights the need for organizations to have complete visibility into their third-party risk exposure in order to manage their overall security posture. This is a reminder for any business that shares customer data with vendors: a written deletion promise is not always enough, and ongoing verification matters. For website owners, online stores, and IT teams that handle customer orders through logistics or analytics partners, the Trezor incident shows how a flaw in a widely used third-party tool can become a route into customer records. A security-first infrastructure and consulting partner such as AEU-I can help organizations map and manage that kind of outside risk exposure with a focus on vendor security and data handling.

How to Protect Yourself

  1. If you get an unexpected email, call or letter claiming to be from Trezor, do not click any links or share personal details; instead contact Trezor through its official website or support channel directly.
  2. Treat any message that creates urgency or asks you to move cryptocurrency or reveal your wallet recovery phrase as a scam, even if it includes your name, address or order number.
  3. Never give anyone the secret recovery phrase that restores your hardware wallet, no matter who they claim to be.
  4. Use a unique, strong password for your Trezor account and for the email address linked to it, and turn on two-factor authentication wherever it is available.
  5. If you believe your data was exposed in this breach, watch for suspicious mail or calls at your shipping address and report them to Trezor and your local authorities.

Vulnerabilities & Fixes

  • CVE-2026-72898 Critical SQL injection vulnerability in Metabase, exploited as a zero-day in the ShipMonk breach; ShipMonk secured the affected systems and improved its security after the incident. View the fix & details →

Terms Explained

  • hardware wallet A physical device that stores the private keys for cryptocurrency offline, making them harder for remote attackers to steal.
  • zero-day A software flaw that is unknown to the vendor and has no patch available when it is first exploited.
  • SQL injection A type of web attack where an attacker inserts malicious code into a database search box or field to view, change or delete data they should not access.
  • CVSS score A standard number from 0 to 10 that rates how severe a security vulnerability is, with 10 being the most critical.
  • Metabase A data analytics and business intelligence tool that companies use to view and query their data.
  • software supply chain attack A breach that starts by compromising a third-party vendor's software or systems and then reaches that vendor's customers.
  • phishing A scam where attackers send fake emails or messages that look real to trick people into giving away passwords or other sensitive information.
  • social engineering Manipulating people rather than software to get them to reveal confidential information or take harmful actions.

Related AEU services

  • AEU-I IT and security consulting