Trezor's Shipping Provider Breach Expands, Affecting 81,000 Customers
Hardware wallet manufacturer **Trezor** has revealed that a data breach at its logistics partner, **ShipMonk**, now impacts an additional 67,000 U.S. customers, bringing the total to 81,000. The incident, linked to a vulnerability in the **Metabase** analytics platform and the **ShinyHunters** extortion group, exposed sensitive customer information including names, addresses, emails, and phone numbers.
Cryptocurrency hardware wallet maker **Trezor** has announced a significant expansion of a previously disclosed data breach impacting its U.S. customers. The incident, stemming from a security lapse at its shipping and logistics provider, **ShipMonk**, now affects a total of 81,000 customers.
Initially, **Trezor** reported on August 13 that approximately 14,000 customers were impacted. The newly revealed 67,000 affected individuals are U.S. customers who placed orders between November 2019 and August 2021. Their full names, email addresses, phone numbers, shipping addresses, and order numbers were exposed.

### Disappointment Over Data Retention
**Trezor** expressed strong disappointment with **ShipMonk**, stating that despite repeated requests and written assurances, the exposed data was not deleted from **ShipMonk**'s systems as per contractual obligations and data policies. The company emphasized that its own systems and operations were not compromised, and all **Trezor** devices remain secure.
### Increased Phishing Risk
Affected customers have been warned to be vigilant against an increased risk of phishing attacks. The leaked information could be leveraged by threat actors for fraudulent emails, calls, or letters, and potentially expose individuals to physical security risks.
### Metabase Vulnerability and ShinyHunters Link
While **Trezor** has not publicly detailed the method of breach at **ShipMonk**, breach notification emails sent to affected customers indicate that attackers exploited a vulnerability in the third-party analytics platform **Metabase**. This aligns with previous reports of a critical SQL injection zero-day vulnerability in **Metabase** being leveraged to gain administrator access and steal data from customer instances.
Further investigation has revealed that **ShipMonk** received extortion emails from the notorious **ShinyHunters** extortion gang, suggesting their involvement in the incident. Other companies, including online form-building platform **Tally** and laptop manufacturer **Framework**, have also reported data breaches linked to compromised **Metabase** instances.
### Previous Trezor-Related Breaches
This incident is not the first time **Trezor** customers have been impacted by third-party data breaches. In January 2024, **Trezor** disclosed a separate breach involving its third-party support ticketing portal, which exposed personal data of approximately 66,000 users. That stolen data was subsequently used in phishing attempts aimed at stealing users' 24-word wallet recovery seeds.