Trezor Customers Hit by Data Breach Via Shipping Partner ShipMonk, Metabase Zero-Day Exploited
Hardware wallet manufacturer **Trezor** has disclosed a data breach impacting nearly 14,000 customers. The incident stemmed from a compromise at their shipping and logistics provider, **ShipMonk**, where attackers exploited a critical zero-day vulnerability in the third-party analytics platform **Metabase**.
Hardware wallet giant **Trezor** has confirmed a data breach affecting almost 14,000 of its customers. The incident was not a direct compromise of **Trezor**'s systems, but rather originated from an attack on their shipping and logistics partner, **ShipMonk**.
During the breach, threat actors gained access to sensitive customer order data, including full names, shipping addresses, email addresses, and phone numbers. The affected customers are primarily located in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal, with orders placed between May 10th and August 8th, 2026.

**Trezor** stated in a blog post, "On Monday, August 10, 2026, one of our shipping providers, **ShipMonk**, informed us of unauthorized access to their systems containing customer data." The company further clarified that 11,742 customers experienced full exposure (name, email, phone number, shipping address), while 1,947 customers had partial exposure (name, city, email).
## No Impact on Trezor Systems or Devices
**Trezor** was quick to reassure users that its own operations and services were not impacted, its internal systems remain uncompromised, and all **Trezor** devices are secure. However, the company issued a strong warning to affected customers to be vigilant against an expected increase in phishing attempts.
"To be clear, our systems were not compromised, and your **Trezor** device is secure, but the affected customers might be targeted by more sophisticated phishing attempts," **Trezor** emphasized. "Scammers can use the leaked information to send fake emails, make fake phone calls, send fraudulent letters, or potentially impersonate banks, crypto exchanges, or even **Trezor**."
## Metabase Zero-Day at the Heart of the Breach
While **Trezor**'s initial disclosure did not detail the attack vector, breach notification emails from **ShipMonk** to its affected customers, reviewed by BleepingComputer, revealed that the attackers exploited a vulnerability in the third-party analytics platform **Metabase**.
**ShipMonk** stated, "On August 6, 2026, **Metabase** informed us that an unauthorized party exploited a vulnerability in **Metabase**'s software to access data related to your account and your customers." **Metabase** has since patched the vulnerability and invalidated all active sessions.
This incident aligns with previous reports of a critical SQL injection zero-day vulnerability in **Metabase** that allowed threat actors to gain administrator access to compromised instances and carry out data theft. Other companies, including laptop maker **Framework** and online form builder **Tally**, have also disclosed data breaches stemming from their compromised **Metabase** instances.
Further investigation by BleepingComputer indicates that **ShipMonk** has also received extortion emails, reportedly from the **ShinyHunters** extortion gang.
## A History of Third-Party Breaches
This is not **Trezor**'s first encounter with a third-party data breach. In January 2024, the company disclosed a separate incident where threat actors accessed its third-party support ticketing portal, exposing the names, usernames, and email addresses of 66,000 users. Attackers subsequently used this stolen information to launch phishing attacks aimed at tricking users into revealing their 24-word recovery seeds.
Similarly, video game distribution giant **Valve** recently notified **Steam** hardware customers in Europe of a data breach after its shipping partner, **CEVA Logistics**, was hacked. These recurring incidents highlight the critical supply chain risks inherent in modern digital operations, underscoring the need for robust third-party vendor security assessments and ongoing vigilance.