Trezor Customers Hit by Expanded Data Breach at Shipping Partner ShipMonk
Hardware wallet giant **Trezor** has revealed that an additional 67,000 U.S. customers have been impacted by a data breach at its shipping provider, **ShipMonk**. The incident, stemming from a zero-day exploit in **Metabase**, exposed sensitive customer information, raising significant concerns about third-party supply chain risks and potential social engineering attacks.
Hardware wallet manufacturer **Trezor** announced on Friday that an additional 67,000 U.S. customers have been affected by a data breach at its shipping provider, **ShipMonk**. This disclosure follows an earlier report last month concerning 13,689 customers.
The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers for purchases made between November 2019 and August 2021. **Trezor** has clarified that the security of its hardware wallets remains unaffected by this incident.
### Disappointment Over Data Retention
**Trezor** expressed strong disappointment with **ShipMonk**'s handling of customer data.
"Throughout our entire relationship with **ShipMonk**, we repeatedly requested and received written assurance confirming the deletion of the data, in line with our contract, data policy, and past communications," **Trezor** stated. "We are very disappointed that, despite receiving this confirmation, the data was not deleted in their systems."
### Breach Details and Timeline
**ShipMonk** informed **Trezor** of unauthorized access to their systems on August 10, 2026. Initially, the breach was believed to be limited to data within **Trezor**'s 90-day data storage policy. However, further investigation revealed a broader impact.
**Trezor**'s policy dictates the deletion or anonymization of all customer data related to a purchase from its eShop after 90 days, a timeframe chosen to cover the entire order lifecycle, including delivery, returns, and refunds.
### Zero-Day Exploit and ShinyHunters Involvement
While **ShipMonk** has not publicly acknowledged the incident, the logistics company reportedly secured the affected systems and enhanced its security post-breach. The digital intrusion involved the zero-day exploitation of **CVE-2026-72898** (CVSS score: 10.0), a critical SQL injection vulnerability in **Metabase**, an open-source business intelligence tool.
Enterprise blockchain security firm **Holborn** attributes the breach to the **ShinyHunters** extortion gang, known for high-profile data theft incidents.
### Mitigating Post-Breach Risks
**Trezor** has directly notified affected customers and issued a strong warning about potential social engineering attacks. Bad actors could leverage the leaked information to craft sophisticated phishing emails, fraudulent calls, or even impersonate **Trezor** in communications to trick targets into compromising their accounts or physical security.
"The leaked information could be used for scam emails, fraudulent calls or letters, and could potentially expose affected individuals to physical security risks," **Trezor** cautioned.
### The Importance of Supply Chain Security
**Holborn** emphasized that this software supply chain attack underscores the critical need for organizations to possess comprehensive visibility into their third-party risk exposure. Such visibility is essential for effectively managing their overall security posture.
"The **Trezor** breach was the result of a supply chain attack beginning with a zero-day vulnerability," **Holborn** explained. "By finding and exploiting the SQL injection flaw in **Metabase**, the attackers were able to exploit several of its customers, stealing sensitive data and extorting the organization."
"In **Trezor**'s case, this meant the exposure of customer order details that were stored in a **Metabase** instance by **ShipMonk**."